logo

Attackers Using Obfuscation Tools to Deliver Multi-Stage Malware via Invoice Phishing

ID: fc2ffec0-d1e0-555e-b918-6225afa0e994

STIX ID: report--fc2ffec0-d1e0-555e-b918-6225afa0e994

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-09

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers observed an active, multi-stage phishing campaign that uses SVG attachments and layered obfuscation (BatCloak and ScrubCrypt) to deploy Venom RAT (and other RAT families) plus a stealer targeting cryptocurrency wallet files; the campaign employs persistence, AMSI/ETW bypasses, and a plugin-based C2 delivery mechanism to expand capabilities and exfiltrate sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.