Gbhackers Phishing Campaign Distributes AsyncRAT, VenomRAT, and XWorm via Fake Invoice PDF
Article Content
- •Phishing emails deliver RATs using fake invoice PDFs as bait.
- •Attack utilizes layered obfuscation and legitimate cloud services for stealth.
- •Defenders should monitor TryCloudflare domains and flag suspicious downloads.
A phishing campaign has been identified that utilizes a fake invoice PDF to deliver multiple remote access trojans (RATs), primarily AsyncRAT, along with VenomRAT and XWorm. The attack begins with a phishing email containing a Dropbox URL leading to a ZIP archive. Upon extraction, the archive reveals a shortcut that connects to a TryCloudflare tunnel, which hosts a series of obfuscated scripts and files. These scripts execute a BAT file that downloads a ZIP file containing malicious Python packages disguised as legitimate files. The campaign employs advanced obfuscation techniques and process injection methods to evade detection. The attackers leverage legitimate cloud services to enhance delivery success. This campaign is reminiscent of an August attack previously analyzed by X-Labs, indicating a trend in the use of legitimate infrastructure for malicious purposes. Security professionals are advised to monitor and block suspicious TryCloudflare domains and flag anomalous downloads.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track AsyncRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AsyncRAT and SideCopy Campaigns Target Users with Multi-Stage Attacks Recent cybersecurity reports detail two significant malware campaigns involving AsyncRAT and SideCopy. The AsyncRAT campaign employs a five-stage infection chain utilizing a socially engineered batch file and the AutoIt interpreter, culminating in a .NET payload that steals information. Meanwhile, the SideCopy group…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…