Fileless Malware Deploys Advanced RAT via Legitimate Tools
ID: 27249282-6422-50fc-8150-b5bb0f249b92
STIX ID: report--27249282-6422-50fc-8150-b5bb0f249b92
Feed Name: Infosecurity Magazine (News)
Researchers uncovered a fileless campaign that abused a compromised ScreenConnect client to run a VBScript/PowerShell loader which loaded payloads into memory and invoked a .NET assembly (Obfuscator.dll) to deploy AsyncRAT. The malware establishes persistence (scheduled task named “Skype Updater”), disables Windows logging, communicates with C2 domains (e.g., 3osch20.duckdns.org), and exfiltrates system information, credentials, browser artifacts and keystrokes, making detection and remediation difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
