BlindEagle Deploys Caminho and DCRAT
ID: 59236248-72df-54a9-a287-3f7af25faf1b
STIX ID: report--59236248-72df-54a9-a287-3f7af25faf1b
Feed Name: Zscaler Security Research Blog
Threat Score
### Executive summary: This report analyzes a targeted phishing campaign by ‘BlindEagle’ that uses a clickable SVG to deliver obfuscated JavaScript and PowerShell which load the Caminho loader in memory and ultimately deploy the DCRAT remote-access trojan via process hollowing; the analysis includes deobfuscation methods, sample code fragments, a Discord-hosted payload URL, and a list of C2 hosts tied to the embedded certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
