logo

From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises

ID: bbf56866-8075-5f91-bb3e-9f9b5e6782d9

STIX ID: report--bbf56866-8075-5f91-bb3e-9f9b5e6782d9

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
78/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: raptur3

...
...

JS.MonoGlyphRAT is an actively observed JavaScript-based RAT/loader that leverages monoglyph identifier obfuscation and Windows Script Host to gain persistence and remote control after users open seemingly benign purchase-order/quote .js attachments; it communicates with C2 over HTTP using custom headers (X-S/X-A), supports AES-encrypted payload delivery, PowerShell stagers, in-memory .NET execution with AMSI bypass, and has confirmed victims across US technology, MSSPs, telecoms and education — ANY.RUN provides sandbox analysis and IOCs to help detect and hunt the infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.