Malicious macros in Excel documents compile embedded C Sharp (C#) source code into an executable file that actually downloads the RAT. The Trojan has survived undetected for so long due to a low instance of infections. The researchers found only 27 total samples extending to December 2015. The RAT collects victim information, updates itself and manipulates settings, becomes a reverse proxy, executes commands and even uninstalls itself. The payload then downloads a file on port 443 and runs the downloaded file using AES-128.”]
Source: https://securityintelligence.com/news/stealthy-remote-access-trojan-resurfaces/

