In Bad Company: JScript RAT and CobaltStrike

General News

Summary

Over the past years, it has been noted that JScript based RATs have often been distributed via phishing campaigns. Once the initial loader script is executed, it contacts a command and control (C&C) server, which responds with a new malicious script. This is the second stage loader and is executed on the fly. The second stage loader communicates with the C&C server to get the RAT component, once again scripted with JScript. The RAT component has the capability to continue running until directed to stop, and execute additional commands received from the C&C server.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software Red Team Software Adversary Simulation Software

Linked Companies