Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » New HTML smuggling company delivers DCRat malware to Russian-speaking users
Global Security

New HTML smuggling company delivers DCRat malware to Russian-speaking users

AdminBy AdminSeptember 27, 2024No Comments3 Mins Read
HTML Smuggling Campaign
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 27, 2024Ravi LakshmananGenAI / Cybercrime

HTML smuggling company

Russian-speaking users have become the target of a new campaign to distribute a commercial Trojan named DCRat (aka DarkCrystal RAT) using a technique known as Contraband HTML.

This development marks the first time malware has been deployed using this method, a departure from previously observed delivery vectors such as compromised or spoofed websites or phishing emails with PDF attachments or Microsoft Excel documents with macro firmware.

“HTML smuggling is primarily a payload delivery mechanism,” – Nikhil Hegde, researcher at Netskope said in an analysis published Thursday. “The payload can be embedded in the HTML itself or retrieved from a remote resource.”

Cyber ​​security

The HTML file, in turn, can be distributed through fake sites or spam campaigns. Once the file is run through the victim’s web browser, the hidden payload is decoded and downloaded to the machine.

The attack then uses some level of social engineering to convince the victim to open the malicious payload.

Netskope said it discovered HTML pages mimicking TrueConf and VK in Russian that, when opened in a web browser, automatically download a password-protected ZIP archive to disk in an attempt to avoid detection. The ZIP payload contains an embedded RarSFX archive that eventually leads to the deployment of the DCRat malware.

First released in 2018, DCRat is capable of functioning as a full-fledged backdoor that can be combined with additional plugins to extend its functionality. It can execute shell commands, record keystrokes, and select files and credentials, among other things.

Organizations are encouraged to review HTTP and HTTPS traffic to ensure systems are not interacting with malicious domains.

This happened at a time when Russian companies were targeted by a threat cluster called “Stone Wolf” which infected them Jellyfish stealer by sending phishing emails pretending to be a legitimate industrial automation solutions provider.

Cyber ​​security

“Adversaries continue to use archives with both malicious files and legitimate attachments that distract the victim” — BI.ZONE said. By using the names and details of real organizations, attackers have a better chance of getting victims to download and open malicious attachments.”

It also follows the emergence of malicious companies that likely used Generative Artificial Intelligence (GenAI) to write the VBScript and JavaScript code responsible for spreading AsyncRAT via HTML smuggling.

“The structure of the scripts, the comments, and the choice of function and variable names were strong clues that the threat actor used GenAI to create the malware,” HP Wolf Security said. said. “These actions show how GenAI is accelerating attacks and lowering the bar for cybercriminals to infect endpoints.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.