Security researchers have unearthed a novel phishing campaign designed to distribute the notorious Remcos RAT (Remote Control and Surveillance Tool). In this campaign, cybercriminals employ a cunning ruse by camouflaging the malware as what appears to be an innocuous payslip, luring unsuspecting users into their trap. Phishing emails, sporting the subject line, 'This is a confirmation document for your payment transfer,' are dispatched, enticing recipients to open the message. Inside the email, a compressed cabinet (CAB) file is included, which, upon execution, releases an executable (EXE) file masquerading as a PDF document icon. Once initiated, the Remcos RAT proceeds to execute a series of malicious actions, encompassing the capture of screenshots, logging keystrokes, and granting cybercriminals control over the victim's webcams and microphones. Additionally, it extracts stored browsing histories and passwords from the victim's web browsers. This isn't the first instance of the Remcos RAT being used for nefarious purposes. In a prior incident in March, Microsoft reported a similar attack where the Remcos RAT was harnessed to target employees at U.S. accounting and tax return preparation firms. Furthermore, the Remcos RAT is a sophisticated malware with multiple layers of obfuscation to evade detection. Its primary propagation method revolves around malicious email attachments, underscoring the importance of organizations implementing rigorous file scanning procedures. The deployment of Intrusion Detection Systems (IDS) can also prove instrumental in swiftly identifying and responding to any abnormal system behaviors. Moreover, the Remcos RAT has gained popularity among cybercriminals, particularly in a campaign featuring the QakBot malware and Knight ransomware since August 2023. Notably, Check Point researchers uncovered a stealthy Remcos RAT campaign that affected 40 major Colombian companies, providing attackers with complete control over compromised systems for malicious intents.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...