Horns&Hooves Campaign Delivers RATs via Fake Emails and JavaScript Payloads
NetSupport RAT and BurnsRAT are being distributed by a recently identified malware operation that primarily targets Russian private users, retailers, and service providers.
The operation, which Kaspersky called Horns&Hooves, has affected over 1,000 people since it started in March 2023. Utilizing the access that these trojans provide, the ultimate objective of these attacks is to install stealer malware, including Meduza and Rhadamanthys.
According to a Monday investigation by security researcher Artem Ushkov, there has been a recent increase in emails that contain lookalike ZIP files that contain JScript scripts. Potential clients' or partners' bids and requests are [passed off] as script files.
The operations' threat actors have shown that they actively develop the JavaScri...

