Socprime
Deno-Based RAT Leveraging Teams Impersonation Targets Employees
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new Remote Access Trojan (RAT) utilizing the Deno JavaScript runtime has been deployed against employees through email flooding and fake Microsoft Teams calls. The attack combines social engineering tactics to overwhelm targets, leading to the download of a malicious archive. The malware operates via multiple modular JavaScript files and uses specific Deno permission flags for command and control communication. Detection occurred during post-exploitation activities rather than initial execution. Organizations are advised to monitor for suspicious Deno executions and Teams impersonation alerts. The attack's scope appears to be significant, affecting multiple organizations. Immediate isolation of affected hosts is recommended upon detection.
Key Points: • A Deno-based RAT is being deployed through email flooding and Teams impersonation. • The malware operates using modular JavaScript files with specific permission flags. • Organizations should implement monitoring for Deno executions and Teams impersonation alerts.