ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins
What it means
MISP EudorIA ha pubblicato l'advisory "ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: ScrubCrypt Deploys VenomRAT with an Arsenal of Plugins. Report from - [URL rimossa] (1712774572) Last year, FortiGuard Labs uncovered the 8220 Gang’s utilization of ScrubCrypt to launch attacks targeting exploitable Oracle WebLogic Servers. ScrubCrypt has been described as an “antivirus evasion tool” that converts executables into undetectable batch files. It offers several options to manipulate malware, making it more challenging for antivirus products to detect. We recently discovered a threat actor distributing a phishing email containing malicious Scalable Vector Graphics (SVG) files. The email lures victims into clicking on an attachment, which downloads a ZIP file containing a Batch file obfuscated with the BatCloak tool. ScrubCrypt is then used to load the final payload, VenomRAT while maintaining a connection with a command and control (C2) server to install plugins on victims’ environments. The plugin files downloaded from the C2 server include VenomRAT version 6, Remcos, XWorm, NanoCore, and a stealer designed for specific crypto wallets. This article provides detailed insights into how the threat actor distributes VenomRAT and other plugins. Click to Enlarge Figure 1: Attack chain ## Initial Access The attacker initiates the attack by sending a phishing email stating that a shipment has been delivered. It also includes an attached invoice. The attachment is an SVG file named “INV0ICE\_#[dominio rimosso],” which contains e
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:50
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 40
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 36Last sharing verification: 2026-09-26T02:02:01.750419+00:00
- MISP event
- f1dd9c3d-94ae-4da4-8ef3-d967315f9810
- Classification
- Medium