From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises
ID: bbf56866-8075-5f91-bb3e-9f9b5e6782d9
STIX ID: report--bbf56866-8075-5f91-bb3e-9f9b5e6782d9
Feed Name: ANY.RUN's Cybersecurity Blog
JS.MonoGlyphRAT is an actively observed JavaScript-based RAT/loader that leverages monoglyph identifier obfuscation and Windows Script Host to gain persistence and remote control after users open seemingly benign purchase-order/quote .js attachments; it communicates with C2 over HTTP using custom headers (X-S/X-A), supports AES-encrypted payload delivery, PowerShell stagers, in-memory .NET execution with AMSI bypass, and has confirmed victims across US technology, MSSPs, telecoms and education — ANY.RUN provides sandbox analysis and IOCs to help detect and hunt the infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
