all InfoSec news
A New Phishing Campaign Deploys STRRAT and VCURMS via GitHub
Malware Analysis, News and Indicators - Latest topics malware.news
There’s a new phishing campaign delivering STRRAT and VCURMS Remote Access Trojans through a malicious Java-based downloader, which we can observe on ANY.RUN.
STRRAT is a Java-based Remote Access Trojan (RAT) that primarily functions as a keylogger, extracting credentials from browsers and applications.
VCURMS is another RAT, possibly connected to the Rude Stealer malware. It runs cmd.exe commands, collects system data and credentials from browsers, Discord, Steam, and other programs. It can also upload additional modules to expand its information-stealing …
access any.run applications browsers campaign can connected credentials downloader functions github java keylogger malicious observe phishing phishing campaign rat remote access remote access trojan remote access trojans run strrat trojan trojans vcurms