FlawedAmmyy RAT  - FlawedAmmyy RAT - Microsoft Publisher File To Deliver Dangerous FlawedAmmyy RAT

A new campaign using Weaponized Publisher File(.pub) to the . The RAT is a backdoor tool that gains remote access to the attacker.

researchers from Trustwave spotted the Email campaign subjected “Payment Advice” with Microsoft Office Publisher file attached.

FlawedAmmyy RAT  - 6a0133f264aa62970b022ad3a9a30c200b - Microsoft Publisher File To Deliver Dangerous FlawedAmmyy RAT

Once the .pub file is opened it asks the victim’s to Enable Macros, the macro script triggers Document_Open() event which opens the file and once the file is opened it access the URL that located in the Tag Property and executes a downloaded file.

FlawedAmmyy RAT  - 6a0133f264aa62970b022ad389f59a200d - Microsoft Publisher File To Deliver Dangerous FlawedAmmyy RAT

At the time of analysis the URL was not active, but with further analysis, it was identified that the URL was used to download the self-extracting archive that contains the FlawedAmmyy RAT.

The FlawedAmmy RAT functions as follows
Remote Desktop control
File system manager
support
Audio Chat

With further analysis in the Cuckoo Sandbox, researchers confirmed that the backdoor accessed a certain IP related to FlawedAmmyy. It transfers the information such as id”, “os”, “names” and credentials from the victim’s machine to attacker’s server.

FlawedAmmyy RAT  - 6a0133f264aa62970b022ad3a9a3a5200b - Microsoft Publisher File To Deliver Dangerous FlawedAmmyy RAT

Researchers said this campaign is unusual and it was originated from the infamous notorious Necurs botnet. The campaign was small and it particularly targets domains belonging to .

With the previous campaign, attackers deliver FlawedAmmyy RAT via Weaponized Microsoft Word and PDF Attachments to spy victims device and steal the sensitive information Remotely.

Also Read

Beware of FlawedAmmyy-RAT that Steals Credentials and Record Audio Chat

Beware !! Hackers Deliver FlawedAmmyy RAT via Weaponized Microsoft Word and PDF Documents

New KeyPass Ransomware Actively Attacking Around the World To Encrypt the Victim Files



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here