DCRAT Impersonating the Colombian Government
July 2, 2025, 4:36 p.m.
Description
A new email attack distributing DCRAT, a Remote Access Trojan, has been uncovered. The threat actor impersonates a Colombian government entity to target organizations in Colombia. The attack employs multiple evasion techniques, including password-protected archives, obfuscation, steganography, base64 encoding, and multiple file drops. DCRAT features a modular architecture, comprehensive surveillance capabilities, information theft functions, system manipulation tools, file and process management, and browser credential harvesting. The attack chain involves a phishing email with a ZIP attachment containing a bat file, which drops an obfuscated vbs file. This file eventually runs a base64-encoded script that downloads and executes the final payload. The RAT employs various persistence mechanisms and anti-analysis techniques. It attempts to bypass Windows Antimalware Scan Interface (AMSI) and continuously tries to connect to its command-and-control server.
Tags
Date
- Created: July 2, 2025, 3:23 p.m.
- Published: July 2, 2025, 3:23 p.m.
- Modified: July 2, 2025, 4:36 p.m.
Indicators
- db21cc64fb7a7ed9075c96600b7e7e7007a0df7cb837189c6551010a6f828590
- b0f3c7ea17875b5e1545678b3878ce268ff4bde718b66254ce01b0bb864801b8
- 77a22e30e4cc900379fd4b04c707d2dfd174858c8e1ee3f1cbecd4ece1fab3fe
- 34b8040d3dad4bd9f34738fbc3363fcda819ac479db8497fb857865cee77ad89
- 176.65.144.19
- https://paste.ee/d/oAqRiS3g
- http://paste.ee/d/jYHEqBJ3/0
- https://ia601205.us.archive.org/26/items/new_image_20250430/new_image.jpg
Additional Informations
- Government
- Colombia