Pirated Microsoft Office delivers malware cocktail on systems
ID: 7c9d04d6-e958-5250-a18c-7a84837c8a64
STIX ID: report--7c9d04d6-e958-5250-a18c-7a84837c8a64
Feed Name: Bleeping Computer
AhnLab ASEC has identified an active campaign distributing a malicious cracked Microsoft Office installer via torrent sites that silently deploys a multi-component malware cocktail — including Orcus RAT, XMRig miner, 3Proxy proxy software, PureCrypter, and AntiAV—by running an obfuscated .NET loader that obtains download URLs from Telegram/Mastodon and fetches PowerShell-encoded payloads hosted on Google Drive/GitHub; the installer also installs a persistent 'Updater' task to reintroduce components after removal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
