New IDAT Loader Attacks Using Steganography to Deploy Remcos RAT
ID: ec5fb219-80c8-5e58-834f-97d733a1b29a
STIX ID: report--ec5fb219-80c8-5e58-834f-97d733a1b29a
Feed Name: The Hacker News
Ukrainian entities in Finland were targeted by a campaign that used IDAT Loader (overlapping with Hijack Loader) and steganographic PNGs to locate and deploy Remcos RAT, an activity attributed to the CERT-UA tracked cluster UAC-0184. CERT-UA also reported related campaigns delivering COOKBOX via Signal-distributed Excel documents and the resurgence of PikaBot, while IDAT/Hijack Loader families have been observed distributing other payloads such as DanaBot, SystemBC, and RedLine Stealer, highlighting active, evolving malware threats in the region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
