UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT
ID: 8836f187-06dd-5036-9f30-e660a0e078a7
STIX ID: report--8836f187-06dd-5036-9f30-e660a0e078a7
Feed Name: The Hacker News
Uptycs researchers attribute a phishing-driven campaign to the UAC-0050 group that delivers Remcos RAT via a malicious LNK file which launches an HTA through mshta.exe and a sequence of PowerShell scripts; the payload uses unnamed pipes between processes to decrypt and launch Remcos (v4.9.2 Pro), establishes persistence as fmTask_dbg.exe, and can harvest system data and browser credentials — the campaign targets Ukrainian and Polish entities and leverages evasion techniques to bypass EDR and antivirus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
