Cybercriminals are abusing the Orcus RAT to target Bitcoin investors with their malicious software. The attack chain starts with phishing messages advertising a new Bitcoin trading bot application called Gunbot developed by GuntherLab. The malicious emails come with a.ZIP attachment that includes a simple VB script that acts as a downloader. The downloaded binary is a Trojanized version of an open source inventory system tool named TTJ-Inventory System. The malicious code uses a hardcoded key to decrypt encoded code into another.NET PE executable that is loaded and executed directly to memory.”]
Source: https://securityaffairs.co/wordpress/66526/malware/orcus-rat-target-bitcoin.html