Tuesday, June 24, 2025
  • Login
Whats Current In
Advertisement
  • Cyber Security
No Result
View All Result
  • Cyber Security
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign

wcisrvadm by wcisrvadm
July 11, 2024
in Cyber Security
0
New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

This post was originally published on this site

Jul 11, 2024NewsroomMalware / Threat Intelligence

Phishing Campaign

Spanish language victims are the target of an email phishing campaign that delivers a new remote access trojan (RAT) called Poco RAT since at least February 2024.

The attacks primarily single out mining, manufacturing, hospitality, and utilities sectors, according to cybersecurity company Cofense.

“The majority of the custom code in the malware appears to be focused on anti-analysis, communicating with its command-and-control center (C2), and downloading and running files with a limited focus on monitoring or harvesting credentials,” it said.

Infection chains begin with phishing messages bearing finance-themed lures that trick recipients into clicking on an embedded URL pointing to a 7-Zip archive file hosted on Google Drive.

Other methods observed include the use of HTML or PDF files directly attached to the emails or downloaded via another embedded Google Drive link. The abuse of legitimate services by threat actors is not a new phenomenon as it allows them to bypass secure email gateways (SEGs).

Cybersecurity

The HTML files propagating Poco RAT, in turn, contain a link that, upon clicking, leads to the download of the archive containing the malware executable.

“This tactic would likely be more effective than simply providing a URL to directly download the malware as any SEGs that would explore the embedded URL would only download and check the HTML file, which would appear to be legitimate,” Cofense noted.

The PDF files are no different in that they also contain a Google Drive link that harbors Poco RAT.

Once launched, the Delphi-based malware establishes persistence on the compromised Windows host and contacts a C2 server in order to deliver additional payloads. It’s so named owing to its use of the POCO C++ Libraries.

The use of Delphi is a sign that the unidentified threat actors behind the campaign are focusing on Latin America, which is known to be targeted by banking trojans written in the programming language.

Phishing Campaign

This connection is strengthened by the fact that the C2 server does not respond to requests originating from infected computers that are not geolocated to the region.

The development comes as malware authors are increasingly using QR codes embedded with PDF files to trick users into visiting phishing pages that are designed to harvest Microsoft 365 login credentials.

Cybersecurity

It also follows social engineering campaigns that use deceptive sites advertising popular software to deliver malware such as RATs and information stealers like AsyncRAT and RisePro.

Similar data theft attacks have also targeted internet users in India with bogus SMS messages falsely claiming of package delivery failures and instructing them to click on a provided link to update their details.

The SMS phishing campaign has been attributed to a Chinese-speaking threat actor called Smishing Triad, which has a history of using compromised or purposefully registered Apple iCloud accounts (e.g., “fredyma514@hlh-web.de”) to send smishing messages for carrying out financial fraud.

“The actors registered domain names impersonating the India Post around June, but were not actively using them, likely preparing for a large-scale activity, which became visible by July,” Resecurity said. “The goal of this campaign is to steal massive amounts of personal identifiable information (PII) and payment data.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.
Previous Post

Microsoft’s Partnership With Middle East AI Firm Under Scrutiny

Next Post

Streamlined Security Solutions: PAM for Small to Medium-sized Businesses

wcisrvadm

wcisrvadm

Next Post
Streamlined Security Solutions: PAM for Small to Medium-sized Businesses

Streamlined Security Solutions: PAM for Small to Medium-sized Businesses

Recent Posts

  • Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue
  • How the US Military Is Redefining Zero Trust
  • US House bans WhatsApp on staff devices over security concerns
  • Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers
  • IBM Pushes for More Collaboration Between Security, Governance

Recent Comments

No comments to show.

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024

Categories

  • Cyber Security

Browse by Category

  • Cyber Security
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cyber Security

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.