Tuesday, May 17, 2022

Malicious Campaign Targets Latin America: delivering commodity RATs

Cisco Talos recently observed a new set of campaigns targeting Latin American countries. These campaigns use a multitude of infection components to deliver two widely popular commodity malware and remote access trojans (RATs): njRAT and AsyncRAT.

We also discovered a .NET-based infection chain builder/crypter binary used to generate the malicious infection artifacts used in recent campaigns, including the ones targeting Latin America. Such builders indicate the author’s intent to bundle malware generation functionalities for easy distribution and use by operators, customers and affiliates.

