
Lampion Malware Uses Obfuscated HTML, Multistage VBS and Rundll32 to Deploy 750MB RAT
A newly observed Lampion malware campaign is targeting Portuguese users with phishing emails disguised as routine financial and administrative messages. Researchers at Acronis Threat Research Unit (TRU) found that the operation relies on oversized, obfuscated HTML and Visual Basic Script (VBS) files before using Windows’ rundll32.exe utility to launch a roughly 750MB remote-access Trojan (RAT). […]
The post Lampion Malware Uses Obfuscated HTML, Multistage VBS and Rundll32 to Deploy 750MB RAT appeared first on Cyber Security News.