Tag: PureRAT

Researchers Expose Phishing Threats Distributing CountLoader and PureRAT
News

Researchers Expose Phishing Threats Distributing CountLoader and PureRAT

A new campaign has been seen that uses phishing attempts to pose as Ukrainian government entities in order to deploy CountLoader, which is subsequently used to dump PureMiner and Amatera Stealer. According to Yurren Wan, a researcher at Fortinet FortiGuard Labs, the phishing emails contain malicious Scalable Vector Graphics (SVG) files that are intended to fool recipients into opening dangerous attachments, as reported by The Hacker News. A Compiled HTML Help (CHM) file is contained in a password-protected ZIP archive that is downloaded using the SVG files in the attack chains that the cybersecurity firm has documented. When the CHM file is started, a series of actions are initiated that lead to the deployment of CountLoader. According to the emails, the National Police of Ukraine h...
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
News

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

As part of an ongoing campaign, threat actors continue to target Mexican organizations in order to distribute a modified version of SystemBC and AllaKore RAT. The activity has been attributed by Arctic Wolf Labs to a financially motivated hacking group called Greedy Sponge. Targeting a broad range of industries, including retail, manufacturing, transportation, capital goods, entertainment, agriculture, the public sector, and commercial services, it is thought to have been operational since early 2021. According to a cybersecurity firm's analysis released last week, the AllaKore RAT payload has been significantly altered to allow threat actors to transmit specific banking credentials and one-of-a-kind authentication data back to their command-and-control (C2) server in order to perpe...