Saturday, May 17, 2025
HomeComputer SecurityBeware !! Orcus RAT Delivered Through Advertisement video Files and Images

Beware !! Orcus RAT Delivered Through Advertisement video Files and Images

Published on

SIEM as a Service

Follow Us on Google News

A new highly sophisticated campaign that delivers the Orcus RAT embedded in video files and Images. The campaign mainly focuses on information stealing and .NET evasion.

The Orcus RAT is capable of steal browser cookies and passwords, launch server stress tests (DDoS attacks), disable the webcam activity light, record microphone input, spoof file extensions, log keystrokes and more.

Morphisec labs detected the ongoing campaign, according to their forensic data it appears the samples are widespread and it used by multiple threat actors.

- Advertisement - Google News

Orcus RAT Initial Attack

The initial attack starts with an persistent VBscript that executes the powershell script that downloads the obfuscated .NET executable.The .NET script obfuscated and encrypted with ConfuserEx an open source obfuscation framework for .NET applications.

Initial dowbloader has been signed with an invalid Notepad++ certificate and it is encrypted with ConfuserEx and by a custom algorithm and it has ability to download additional modules form paste.ee & bit.ly.

The downloaded executable performs a UAC registry bypass and through windows mscfile registry technique and escalate the process with highest privileges.

The downloader downloads the themed Coca-Cola advertising video that contains an embedded .NET Orcus RAT. The video looks harmless but it contains an .NET executable which represents the Orcus RAT.

Attached Orcus executable is delivered with AES encrypted settings (the SIGNATURE string is the key). By having all the decryption keys and the encrypted setting in hand, we easily extracted the full xml settings for the RAT, reads morphisec report.

The Orcus RAT advertised as a remote administration tool like TeamViewer and other applications, but it is not a clean app, it has the ability to receive cookies form the browser, it has been sold for $70 and it is capable of recovering passwords from famous applications such as Chrome, Firefox and Filezilla.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...

New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads

A newly identified ransomware campaign has emerged, seemingly targeting supporters of Elon Musk through...

Printer Company Distributes Malicious Drivers Infected with XRed Malware

Procolored, a printer manufacturing company, has been found distributing software drivers infected with malicious...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw affecting the Eventin plugin, a popular event management solution for...

Sophisticated NPM Attack Leverages Google Calendar2 for Advanced Communication

A startling discovery in the npm ecosystem has revealed a highly sophisticated malware campaign...

New Ransomware Attack Targets Elon Musk Supporters Using PowerShell to Deploy Payloads

A newly identified ransomware campaign has emerged, seemingly targeting supporters of Elon Musk through...