Android and Windows RATs Distributed Via Online Meeting Lures
ID: 993b52e2-2bc9-545b-84d9-cb148d02777b
STIX ID: report--993b52e2-2bc9-545b-84d9-cb148d02777b
Feed Name: Security Boulevard
Zscaler ThreatLabz discovered an active campaign (Dec 2023–Jan 2024) in which a threat actor hosted multiple fraudulent Skype/Google Meet/Zoom websites on a shared IP to distribute RATs: SpyNote APKs for Android and NjRAT/DCRat for Windows. Users who click Android or Windows download links receive malicious APKs or BAT files that fetch and execute RAT payloads (some delivered as packed WinRAR archives), with open directories exposing additional executables; the report includes observed domains, filenames, sandbox detections, and mapped MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
