EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins. Report from - [URL rimossa] (1712774572) Last year, FortiGuard Labs uncovered the 8220 Gang’s utilization of ScrubCrypt to launch attacks targeting exploitable Oracle WebLogic Servers. ScrubCrypt has been described as an “antivirus evasion tool” that converts executables into undetectable batch files. It offers several options to manipulate malware, making it more challenging for antivirus products to detect. We recently discovered a threat actor distributing a phishing email containing malicious Scalable Vector Graphics (SVG) files. The email lures victims into clicking on an attachment, which downloads a ZIP file containing a Batch file obfuscated with the BatCloak tool. ScrubCrypt is then used to load the final payload, VenomRAT while maintaining a connection with a command and control (C2) server to install plugins on victims’ environments. The plugin files downloaded from the C2 server include VenomRAT version 6, Remcos, XWorm, NanoCore, and a stealer designed for specific crypto wallets. This article provides detailed insights into how the threat actor distributes VenomRAT and other plugins. Click to Enlarge Figure 1: Attack chain ## Initial Access The attacker initiates the attack by sending a phishing email stating that a shipment has been delivered. It also includes an attached invoice. The attachment is an SVG file named “INV0ICE\_#[dominio rimosso],” which contains e

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:50
Sharing
TLP:CLEAR
Indicators reported by the source
40
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
36Last sharing verification: 2026-09-26T02:02:01.750419+00:00
MISP event
f1dd9c3d-94ae-4da4-8ef3-d967315f9810
Classification
Medium
Open the original source