• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Security Researchers Discovered that the fake emails distribute Remcos RAT Variant

6088

Security Researchers Discovered that the fake emails distribute Remcos RAT Variant

The researchers have discovered a new campaign that spreads a new variant of Remcos RAT that involves an email and the email id pretends to be from a valid domain and the body of the email contains the payment advisory which is used as a technique to convince the victims to get in the attached ZIP file which is a Windows Shortcut but to the user it is displayed as .TXT file. Once the user gets to click the .TXT file and assigns the password it fetches the password and it continues to execute a PowerShell script.

All the communication between the Remcos and its command is encrypted using the RC4. When the PowerShell script executes then it stores the ".exe" string in a variable. It generates and decodes the original path and performs a file extension then starts the dropped file by calling the "Start-Process" PowerShell cmdlet.

The RemcosRAT campaign uses Autult wrapper to deliver the variant featuring new obfuscation and anti-debugging techniques. This threat was encountered by the Trend Micro by encountering the email that was disguised as an order notification but actually delivers the RAT. The researchers found that the Remcos RAT that is infused with a fake email contains a highly customizable form of trojan malware.

Tags:
jacob
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related News in Security Researchers Discovered that the fake emails distribute Remcos RAT Variant

Related News in Security Researchers Discovered that the fake emails distribute Remcos RAT Variant

New strain of Emotet banking Trojan spreading internally like Worm
New strain of Emotet banking Trojan spreading internally like Worm
Jul 24, 2017
Security Researchers Discovered that the fake emails distribute Remcos RAT Variant
Security Researchers Discovered that the fake emails distribute Remcos RAT Variant
Oct 28, 2019
Anubis Android trojan spotted stealing PayPal credentials and locking devices
Anubis Android trojan spotted stealing PayPal credentials and locking devices
Apr 11, 2019
Android App With 100M Downloads affected by Trojan Dropper Malware
Android App With 100M Downloads affected by Trojan Dropper Malware
Sep 6, 2019
Android Users from Australia Targeted By Trojan
Android Users from Australia Targeted By Trojan
Apr 15, 2019
Trickbot Trojan Goes past Proofpoint Gateway Using Google Docs
Trickbot Trojan Goes past Proofpoint Gateway Using Google Docs
Sep 6, 2019
Newly discovered BasBanke banking trojan found targeting Brazilian users
Newly discovered BasBanke banking trojan found targeting Brazilian users
Apr 10, 2019
Clicker Trojan Infected iOS Apps Are Taken Down By Apple
Clicker Trojan Infected iOS Apps Are Taken Down By Apple
Oct 30, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Owen ?
How to add SSH key to my Gitlab account

I need to add the SSH key in my gitlab account. How to do so ????

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.