New IDAT loader version uses steganography to push Remcos RAT
ID: 5af9520d-1f2d-5f11-8464-65c014fbb2c2
STIX ID: report--5af9520d-1f2d-5f11-8464-65c014fbb2c2
Feed Name: Bleeping Computer
Threat Score
Morphisec and other researchers observed UAC-0184 using steganographic PNG images and a modular loader (IDAT) to deploy Remcos RAT (and reportedly other families) against a Ukrainian-affiliated organization in Finland; the chain uses in-memory decryption, runtime API resolution, and code injection to evade detection, and CERT-UA published related IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
