Blog | G5 Cyber Security

Crooks abused the Orcus RAT to target Bitcoin investors

Cybercriminals are abusing the Orcus RAT to target Bitcoin investors with their malicious software. The attack chain starts with phishing messages advertising a new Bitcoin trading bot application called Gunbot developed by GuntherLab. The malicious emails come with a.ZIP attachment that includes a simple VB script that acts as a downloader. The downloaded binary is a Trojanized version of an open source inventory system tool named TTJ-Inventory System. The malicious code uses a hardcoded key to decrypt encoded code into another.NET PE executable that is loaded and executed directly to memory.”]

Source: https://securityaffairs.co/wordpress/66526/malware/orcus-rat-target-bitcoin.html

Exit mobile version