EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 55/100

MISP EudorIA ha pubblicato l'advisory "ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins. Report from - [URL rimossa] (1712774572) Last year, FortiGuard Labs uncovered the 8220 Gang’s utilization of ScrubCrypt to launch attacks targeting exploitable Oracle WebLogic Servers. ScrubCrypt has been described as an “antivirus evasion tool” that converts executables into undetectable batch files. It offers several options to manipulate malware, making it more challenging for antivirus products to detect. We recently discovered a threat actor distributing a phishing email containing malicious Scalable Vector Graphics (SVG) files. The email lures victims into clicking on an attachment, which downloads a ZIP file containing a Batch file obfuscated with the BatCloak tool. ScrubCrypt is then used to load the final payload, VenomRAT while maintaining a connection with a command and control (C2) server to install plugins on victims’ environments. The plugin files downloaded from the C2 server include VenomRAT version 6, Remcos, XWorm, NanoCore, and a stealer designed for specific crypto wallets. This article provides detailed insights into how the threat actor distributes VenomRAT and other plugins. Click to Enlarge Figure 1: Attack chain ## Initial Access The attacker initiates the attack by sending a phishing email stating that a shipment has been delivered. It also includes an attached invoice. The attachment is an SVG file named “INV0ICE\_#[dominio rimosso],” which contains e

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:50
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
40
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
36Ultima verifica di condivisione: 2026-09-26T02:02:01.750419+00:00
Evento MISP
f1dd9c3d-94ae-4da4-8ef3-d967315f9810
Classificazione
Media
Apri la fonte originale