PowerShell
-
State-sponsored XenoRAT campaign targets South Korean embassies, researchers say
A Trellix-led analysis describes a multi-phase, state-sponsored XenoRAT espionage campaign targeting South Korean embassies, with links to North Korea’s Kimsuky and indications of possible China-based sponsorship. The operation has conducted at least 19 spearphishing attacks since March, delivering XenoRAT via password-protected ZIP archives and complex, multilingual lures.
-
Cybersecurity Experts Uncover New PowerShell Attack Leveraging Remcos RAT
Qualys Threat Research Unit reveals a new cyberattack method leveraging PowerShell to deploy Remcos RAT on systems, allowing hackers to operate undetected and carry out unauthorized surveillance and data theft.