ThreatLabz
ID: 3caeb3f7-3ec9-547c-b656-4f4e9985603a
STIX ID: report--3caeb3f7-3ec9-547c-b656-4f4e9985603a
Feed Name: Zscaler Security Research Blog
Threat Score
Case study of a OneNote-based malware campaign (since December 2022) that distributes Remote Access Trojans including AsyncRAT by embedding an obfuscated batch file and PowerShell payloads inside .one documents; researchers recovered and deobfuscated encrypted blobs (base64/AES/gzip), extracted PE files packed with AgileDotNet, and identified AsyncRAT after unpacking with de4dot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
