Fake Employee Reports Spread Guloader and Remcos RAT Malware
ID: f1828428-4451-5d43-8325-7cbb181a4829
STIX ID: report--f1828428-4451-5d43-8325-7cbb181a4829
Feed Name: HackRead
AhnLab reports a phishing campaign that lures recipients with fake performance-review emails containing a zipped attachment named to appear as a PDF but actually an executable ('staff record pdf.exe'). Executing the file launches Guloader (fileless behavior, fetching components from Google Drive) which then delivers Remcos RAT — enabling remote access, webcam/microphone surveillance, keylogging and credential theft. The report includes IOCs (196.251.116.219 and ports 2404/5000) and advises users to show file extensions and exercise caution with unexpected HR/termination-related attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
