logo

SiMay RAT Spreads Via Telegram Phishing Site

ID: 2adb7944-6cda-578a-a411-f4da211bad15

STIX ID: report--2adb7944-6cda-578a-a411-f4da211bad15

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

A multi-stage malware campaign uses a phishing site masquerading as Telegram to deliver a trojanized MSI that drops a downloader which retrieves staged .dat files and compressed payloads from note.youdao.com; the campaign employs DLL side-loading, process injection, encrypted shellcode, and ultimately deploys a Gh0st RAT-like remote access trojan with keylogging and espionage capabilities, targeting Chinese-speaking users and reusing infrastructure/identifiers tied to a previously reported SiMay actor. IoCs (URLs, IP, and multiple file hashes) and recommended mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.