Attackers Using Obfuscation Tools to Deliver Multi-Stage Malware via Invoice Phishing
ID: fc2ffec0-d1e0-555e-b918-6225afa0e994
STIX ID: report--fc2ffec0-d1e0-555e-b918-6225afa0e994
Feed Name: The Hacker News
Threat Score
Researchers observed an active, multi-stage phishing campaign that uses SVG attachments and layered obfuscation (BatCloak and ScrubCrypt) to deploy Venom RAT (and other RAT families) plus a stealer targeting cryptocurrency wallet files; the campaign employs persistence, AMSI/ETW bypasses, and a plugin-based C2 delivery mechanism to expand capabilities and exfiltrate sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
