Trend Micro researchers say a new version of the SpyAgent malware has been targeting a legitimate Russian remote access tool called Safib Assistant. The threat actors use social engineering techniques, such as running “earn cryptocurrency for browsing” advertisements, to direct victims to the fake websites. The campaign also uses remote access Trojans such as Remcos RAT, NanoCore, njRAT and AsyncRAT, the researchers say. SpyAgent’s malware dropper is distributed using fake cryptocurrency-related websites in the Russian language.”]
Source: https://www.databreachtoday.com/hackers-abuse-remote-access-tools-to-steal-crypto-data-a-18029