started · updated
Cybersecurity threats involve SloppyRAT malware and university-themed phishing
Cybersecurity researchers have identified two distinct malware campaigns utilizing remote-access trojans (RATs) to facilitate unauthorized access and potential ransomware operations.
A new Windows-based malware named SloppyRAT has been observed using a multi-stage ClickFix delivery chain. The attack leverages the legacy Windows finger.exe utility to retrieve batch scripts, which then use legitimate tools like curl.exe and IronPython to execute a compressed Python payload. This process allows the malware to perform host reconnaissance, enumerate processes, and support lateral movement for ransomware affiliates.
Separately, threat actors are conducting phishing campaigns by impersonating university leadership, including officials from Notre Dame and the University of Virginia. These emails use fabricated allegations of sexual misconduct to trick recipients into clicking links that lead to Google Drive files. These files ultimately download a malicious instance of the legitimate remote management tool Zoho Assist, granting attackers access to sensitive documents and emails.
Entities
Cofense Intelligence · Notre Dame · ThreatLabz · University of Virginia · Zoho Assist