Cisco Talos has observed a malware campaign that utilizes malicious Microsoft Office documents (maldocs) to spread a remote access trojan (RAT) we’re calling “ObliqueRAT” This campaign appears to target organizations in Southeast Asia. Network based detection, although important, should be combined with endpoint protections to combat this threat. This campaign also shows that while network-based detection is important, it can be complemented with system behavior analysis and endpoint protections for additional layers of security. Analyses of the two campaigns of ObliqueRAT and CrimsonRAT show us the changes in tactics and techniques of the attackers used to continue attacks.”]
Source: https://blog.talosintelligence.com/2020/02/obliquerat-hits-victims-via-maldocs.html

