menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Cyber Crime News

>

A new file...
source image

Securityaffairs

1M

read

190

img
dot

A new fileless variant of Remcos RAT observed in the wild

  • Fortinet researchers discovered a new phishing campaign spreading a variant of the commercial malware Remcos RAT.
  • The phishing messages contain a malicious Excel document disguised as an order file to trick the recipient into opening the document. Upon opening the file, the RCE vulnerability CVE-2017-0199 is exploited.
  • The HTA file is wrapped in multiple layers using different script languages and encoding methods to evade detection.
  • The malicious code downloads an encrypted Remcos RAT file from a remote server, executes it as a fileless version directly into memory, allowing attackers to remotely control the infected system.

Read Full Article

like

11 Likes

For uninterrupted reading, download the app