Wednesday, April 23, 2025
HomeComputer SecurityBeware !! Orcus RAT Delivered Through Advertisement video Files and Images

Beware !! Orcus RAT Delivered Through Advertisement video Files and Images

Published on

SIEM as a Service

Follow Us on Google News

A new highly sophisticated campaign that delivers the Orcus RAT embedded in video files and Images. The campaign mainly focuses on information stealing and .NET evasion.

The Orcus RAT is capable of steal browser cookies and passwords, launch server stress tests (DDoS attacks), disable the webcam activity light, record microphone input, spoof file extensions, log keystrokes and more.

Morphisec labs detected the ongoing campaign, according to their forensic data it appears the samples are widespread and it used by multiple threat actors.

- Advertisement - Google News

Orcus RAT Initial Attack

The initial attack starts with an persistent VBscript that executes the powershell script that downloads the obfuscated .NET executable.The .NET script obfuscated and encrypted with ConfuserEx an open source obfuscation framework for .NET applications.

Initial dowbloader has been signed with an invalid Notepad++ certificate and it is encrypted with ConfuserEx and by a custom algorithm and it has ability to download additional modules form paste.ee & bit.ly.

The downloaded executable performs a UAC registry bypass and through windows mscfile registry technique and escalate the process with highest privileges.

The downloader downloads the themed Coca-Cola advertising video that contains an embedded .NET Orcus RAT. The video looks harmless but it contains an .NET executable which represents the Orcus RAT.

Attached Orcus executable is delivered with AES encrypted settings (the SIGNATURE string is the key). By having all the decryption keys and the encrypted setting in hand, we easily extracted the full xml settings for the RAT, reads morphisec report.

The Orcus RAT advertised as a remote administration tool like TeamViewer and other applications, but it is not a clean app, it has the ability to receive cookies form the browser, it has been sold for $70 and it is capable of recovering passwords from famous applications such as Chrome, Firefox and Filezilla.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploit Cloudflare Tunnel Infrastructure to Deploy Multiple Remote Access Trojans

The Sekoia TDR (Threat Detection & Research) team has reported on a sophisticated network...

Threat Actors Leverage npm and PyPI with Impersonated Dev Tools for Credential Theft

The Socket Threat Research Team has unearthed a trio of malicious packages, two hosted...

Hackers Exploit Legitimate Microsoft Utility to Deliver Malicious DLL Payload

Hackers are now exploiting a legitimate Microsoft utility, mavinject.exe, to inject malicious DLLs into...

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network...

Latest Lumma InfoStealer Variant Found Using Code Flow Obfuscation

Researchers have uncovered a sophisticated new variant of the notorious Lumma InfoStealer malware, employing...

Magecart Launches New Attack Using Malicious JavaScript to Steal Credit Card Data

The notorious Magecart group has been identified by the Yarix Incident Response Team as...