Targeted Attack Delivers Crimson RAT
ID: 265cc0a7-d9ec-528b-87d8-83b77905dda8
STIX ID: report--265cc0a7-d9ec-528b-87d8-83b77905dda8
Feed Name: Zscaler Security Research Blog
Zscaler documents two targeted spear-phishing campaigns that deliver Crimson RAT to victims via either a malicious PE with embedded ZIPs or a DOC file with macros; upon execution the RAT performs data exfiltration, screenshots, process control, keylogging and credential theft, connecting to a hardcoded C2 (181.215.47.169) across multiple ports. The report includes command mappings, C2 protocol details, comprehensive IOCs (URLs, IP:port combinations, and multiple file hashes), and notes that Zscaler Cloud Sandbox and Cloud IPS provide detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
