Alert: Cybercriminals Deploying VCURMS and STRRAT Trojans via AWS and GitHub

Teilen:

A new phishing campaign has been observed delivering remote access trojans (RAT) such as VCURMS and STRRAT by means of a malicious Java-based downloader.

“The attackers stored malware on public services like Amazon Web Services (AWS) and GitHub, employing a commercial protector to avoid detection of the malware,” Fortinet FortiGuard Labs researcher Yurren Wan said.

An unusual aspect of the campaign is VCURMS’ use of a Proton Mail email address (“sacriliage@proton[.]me”) for communicating with a command-and-control (C2) server.

The attack chain commences with a phishing email that urges recipients to click on a button to verify payment information, resulting in the download of a malicious JAR file (“Payment-Advice.jar”) hosted on AWS.

Executing the JAR file leads to the retrieval of two more JAR files, which are then run separately to launch the twin trojans.

Besides sending an email with the message “Hey master, I am online” to the actor-controlled address, VCURMS RAT periodically checks the mailbox for emails with specific subject lines to extract the command to be executed from the body of the missive.

This includes running arbitrary commands using cmd.exe, gathering system information, searching and uploading files of interest, and downloading additional information stealer and keylogger modules from the same AWS endpoint.

The information stealer comes fitted with capabilities to siphon sensitive data from apps like Discord and Steam, credentials, cookies, and auto-fill data from various web browsers, screenshots, and extensive hardware and network information about the compromised hosts.

VCURMS is said to share similarities with another Java-based infostealer codenamed Rude Stealer, which emerged in the wild late last year. STRRAT, on the other hand, has been detected in the wild since at least 2020, often propagated in the form of fraudulent JAR files.

“STRRAT is a RAT built using Java, which has a wide range of capabilities, such as serving as a keylogger and extracting credentials from browsers and applications,” Wan noted.

The disclosure comes as Darktrace revealed a novel phishing campaign that’s taking advantage of automated emails sent from the Dropbox cloud storage service via “no-reply@dropbox[.]com” to propagate a bogus link mimicking the Microsoft 365 login page.

“The email itself contained a link that would lead a user to a PDF file hosted on Dropbox, that was seemingly named after a partner of the organization,” the company said. “the PDF file contained a suspicious link to a domain that had never previously been seen on the customer’s environment, ‘mmv-security[.]top.'”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:08 pm, Juni 21, 2025
Wetter-Symbol 30°C
L: 28° | H: 31°
light rain
Luftfeuchtigkeit: 40 %
Druck: 1016 mb
Wind: 8 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.34 mm
Wolken: 97%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
28° | 31°°C 0.73 mm 73% 10 mph 51 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 26°°C 1 mm 100% 15 mph 78 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 23°°C 0 mm 0% 13 mph 78 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
18° | 27°°C 0.38 mm 38% 11 mph 82 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 8 mph 41 % 1016 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 29°°C 0 mm 0% 10 mph 39 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 25°°C 0.73 mm 73% 7 mph 51 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 1 mm 100% 7 mph 77 % 1013 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 78 % 1013 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 67 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 48 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,891.14
-1.99%
Ethereum(ETH)
€2,100.11
-4.58%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.84
-2.23%
Solana(SOL)
€122.21
-3.85%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.139316
-5.61%
Shiba Inu(SHIB)
€0.000010
-4.64%
Pepe(PEPE)
€0.000009
-5.26%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen