None
EN
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
The threat actor known as TA558 has been attributed to a fresh set of attacks delivering various remote access trojans (RATs) like Venom RAT to breach hotels in Brazil and Spanish-speaking markets.
"The threat actors continue to employ phishing emails with invoice themes to deliver Venom RAT implants via JavaScript loaders and PowerShell downloaders," the company said.
The downloader, as the name implies, fetches two additional payloads: a loader that's responsible for launching the Venom RAT malware.
Based on the open-source Quasar RAT, Venom RAT is a commercial tool that's offered for $650 for a lifetime license.
To accomplish this, it modifies the Discretionary Access Control List (DACL) associated with the running process to remove any permissions that could interfere with its functioning, and terminates any running process that matches any of the hard-coded processes.
['malware'
'rat'
'hotel'
'brazil'
'threat'
'running'
'kaspersky'
'set'
'deploy'
'terminate'
'ta558'
'aigenerated'
'process'
'uses'
'scripts'
'venom'
'attacks'
'script']