Microsoft warns: RevengeRat is the new malware that steals passwords, webcam and browser data

Sharing is Caring!

Microsoft has issued an alert over a remote access tool (RAT) dubbed RevengeRAT that it says has been used to target aerospace and travel sectors with spear-phishing emails.

RevengeRAT, also known as AsyncRAT, is being distributed via carefully crafted email messages that prompt employees to open a file masquerading as an Adobe PDF file attachment that in fact downloads a malicious visual basic (VB) file.

According to Microsoft, the phishing emails distribute a loader that then delivers RevengeRAT or AsyncRAT. Morphisec says it also delivers the RAT Agent Tesla.

See also  Kim Jong Un Tests Undersea Drone, Warns of 'Radioactive Tsunami'

“The campaign uses emails that spoof legitimate organizations, with lures relevant to aviation, travel, or cargo. An image posing as a PDF file contains an embedded link (typically abusing legitimate web services) that downloads a malicious VBScript, which drops the RAT payloads,” Microsoft said.

MORE

www.zdnet.com/article/microsoft-warns-watch-out-for-this-new-malware-that-steals-passwords-webcam-and-browser-data/

 

 

h/t DeploraVision

Trending:
See also  They will try to ban crypto now - SVB and Signature Bank both had big crypto exposure - Now IMF warns about crypto.

Views: 0

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.