Threat actors have been looking to covertly take over Windows systems in a new phishing campaign involving the novel MostereRAT trojan, Infosecurity Magazine reports.
Malicious emails purporting to be legitimate business inquiries have been delivered to lure targets into clicking a link that prompts the download of a Word file with a concealed archive that orders subsequent opening of an embedded executable containing MostereRAT, according to an analysis from Fortinet's FortiGuard Labs.
Aside from enabling keylogging and system data gathering, MostereRAT also facilitates the download and execution of various payloads while running remote access tools and establishing hidden admin accounts. MostereRAT also prevents detection by not only averting antivirus traffic and deactivating security systems but also ensuring secure command-and-control communications.
"While this malware uses some creative techniques to evade detection by chaining together novel scripting languages with trusted remote access tools, it is still following a common pattern of exploiting overprivileged users and endpoints without application control," said BeyondTrust Field Chief Technology Officer James Maude.
Malicious emails purporting to be legitimate business inquiries have been delivered to lure targets into clicking a link that prompts the download of a Word file with a concealed archive that orders subsequent opening of an embedded executable containing MostereRAT, according to an analysis from Fortinet's FortiGuard Labs.
Aside from enabling keylogging and system data gathering, MostereRAT also facilitates the download and execution of various payloads while running remote access tools and establishing hidden admin accounts. MostereRAT also prevents detection by not only averting antivirus traffic and deactivating security systems but also ensuring secure command-and-control communications.
"While this malware uses some creative techniques to evade detection by chaining together novel scripting languages with trusted remote access tools, it is still following a common pattern of exploiting overprivileged users and endpoints without application control," said BeyondTrust Field Chief Technology Officer James Maude.
