Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Remcos RAT Campaign Uses Trojanized VeraCrypt Installers to Steal Credentials

## Cybersecurity: Remcos RAT Campaign Targeting South Korea

Cybersecurity: Remcos RAT Campaign Targeting South Korea

The AhnLab Security Intelligence Center (ASEC) has identified an active Remcos RAT campaign specifically targeting users in South Korea. This malware is distributed through various channels, often disguised as VeraCrypt utilities or tools associated with illegal online gambling activities.

The malware, once installed, can steal login credentials, monitor user activities, and provide remote control over affected systems. It is often disguised as a "Blocklist User DB Lookup" program within illegal gambling circles, a term used for accounts flagged due to suspicious activities. The program's interface simulates querying a command-and-control (C2) server for checking these accounts.

The malware is distributed through web browsers and Telegram under filenames such as:

%USERPROFILE%\downloads\programs***usercon.exe %USERPROFILE%\downloads\telegram desktop***usercon.exe %USERPROFILE%\downloads\programs\blackusernon.exe

These filenames and GUI strings suggest its use as a tool for operators of illegal sports-betting and casino sites. The specific websites for initial distribution remain unknown, but the theme indicates focused targeting within this underground ecosystem.

Technical Details: DB Lookup Tool and VeraCrypt Installer

The fake lookup program's login function is non-operational and acts as a decoy. It contains two malicious VBS scripts embedded in its resource section, which execute when the program runs, starting the infection chain silently. A second variant impersonates a VeraCrypt utility installer, delivered as installer.exe. It is packed as a 7z self-extracting archive, also containing a malicious VBS script.

The AhnLab Security Intelligence Center (ASEC) has identified an active Remcos RAT campaign specifically targeting users in South Korea.
Olivia Harper · Thehackingpost

The attack chain involves multiple scripted stages and significant obfuscation to evade detection. The stages include:

Installer: Fake DB tool / VeraCrypt VBS downloader: %TEMP%[Random].vbs VBS dropper: XX12.JPG VBS downloader: Config.vbs VBS downloader: L1k9.JPG PowerShell downloader: NMA1.JPG Injector: XIN_PHOTO.JPG Remcos RAT payload: Aw21.JPG

The threat actor embeds Base64-encoded PE payloads inside files that masquerade as JPG images, passing through five scripted stages to ultimately drop and execute a .NET-based injector. This injector logs execution details and downloads the Remcos RAT payload from a specified URL.

Remcos RAT is a commercially available remote administration tool often misused for malicious activities. It offers capabilities such as:

Remote command execution, file management, and process control Keylogging and clipboard monitoring Screenshot capture and surveillance via webcam and microphone Theft of stored credentials from web browsers and other applications

Advertisement

The analyzed samples store configuration data in an encrypted resource labeled "SETTINGS." These configurations include C2 servers and other parameters. Some variants use Korean strings in mutex names and registry keys, suggesting localization for South Korean targets.

The campaign indicates active targeting of South Korean users, especially those involved in illegal online gambling. The use of fake VeraCrypt installers shows that general users can also be affected if they download software from untrusted sources.

Users and organizations should refrain from downloading software from unknown sources, verify installers through trusted channels, and use up-to-date security solutions capable of detecting script-based threats. Systems suspected of infection should be isolated, scanned thoroughly, and have all credentials changed post-remediation.

For further updates, follow us on Google News , LinkedIn , and X .

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories