Remcos RAT Campaign Uses Trojanized VeraCrypt Installers to Steal Credentials
## Cybersecurity: Remcos RAT Campaign Targeting South Korea
Cybersecurity: Remcos RAT Campaign Targeting South Korea
The AhnLab Security Intelligence Center (ASEC) has identified an active Remcos RAT campaign specifically targeting users in South Korea. This malware is distributed through various channels, often disguised as VeraCrypt utilities or tools associated with illegal online gambling activities.
The malware, once installed, can steal login credentials, monitor user activities, and provide remote control over affected systems. It is often disguised as a "Blocklist User DB Lookup" program within illegal gambling circles, a term used for accounts flagged due to suspicious activities. The program's interface simulates querying a command-and-control (C2) server for checking these accounts.
The malware is distributed through web browsers and Telegram under filenames such as:
%USERPROFILE%\downloads\programs***usercon.exe %USERPROFILE%\downloads\telegram desktop***usercon.exe %USERPROFILE%\downloads\programs\blackusernon.exe
These filenames and GUI strings suggest its use as a tool for operators of illegal sports-betting and casino sites. The specific websites for initial distribution remain unknown, but the theme indicates focused targeting within this underground ecosystem.
Technical Details: DB Lookup Tool and VeraCrypt Installer
The fake lookup program's login function is non-operational and acts as a decoy. It contains two malicious VBS scripts embedded in its resource section, which execute when the program runs, starting the infection chain silently. A second variant impersonates a VeraCrypt utility installer, delivered as installer.exe. It is packed as a 7z self-extracting archive, also containing a malicious VBS script.
The AhnLab Security Intelligence Center (ASEC) has identified an active Remcos RAT campaign specifically targeting users in South Korea.
The attack chain involves multiple scripted stages and significant obfuscation to evade detection. The stages include:
Installer: Fake DB tool / VeraCrypt VBS downloader: %TEMP%[Random].vbs VBS dropper: XX12.JPG VBS downloader: Config.vbs VBS downloader: L1k9.JPG PowerShell downloader: NMA1.JPG Injector: XIN_PHOTO.JPG Remcos RAT payload: Aw21.JPG
The threat actor embeds Base64-encoded PE payloads inside files that masquerade as JPG images, passing through five scripted stages to ultimately drop and execute a .NET-based injector. This injector logs execution details and downloads the Remcos RAT payload from a specified URL.
Remcos RAT is a commercially available remote administration tool often misused for malicious activities. It offers capabilities such as:
Remote command execution, file management, and process control Keylogging and clipboard monitoring Screenshot capture and surveillance via webcam and microphone Theft of stored credentials from web browsers and other applications
The analyzed samples store configuration data in an encrypted resource labeled "SETTINGS." These configurations include C2 servers and other parameters. Some variants use Korean strings in mutex names and registry keys, suggesting localization for South Korean targets.
The campaign indicates active targeting of South Korean users, especially those involved in illegal online gambling. The use of fake VeraCrypt installers shows that general users can also be affected if they download software from untrusted sources.
Users and organizations should refrain from downloading software from unknown sources, verify installers through trusted channels, and use up-to-date security solutions capable of detecting script-based threats. Systems suspected of infection should be isolated, scanned thoroughly, and have all credentials changed post-remediation.
For further updates, follow us on Google News , LinkedIn , and X .
Based on reporting by GBHackers.
