Spear-Phishing Campaign Abuses Argentine Federal Court Rulings to Deliver Covert RAT
Seqrite Labs has identified a spear-phishing campaign targeting the judicial sector in Argentina, utilizing a Rust-based Remote Access Trojan (RAT). The operation employs a multi-stage infection chain to infiltrate legal institutions and organizations.
Seqrite Labs has identified a spear-phishing campaign targeting the judicial sector in Argentina, utilizing a Rust-based Remote Access Trojan (RAT). The operation employs a multi-stage infection chain to infiltrate legal institutions and organizations.
The campaign focuses on Argentina's judicial institutions, legal professionals, and related government and academic organizations. Attackers use legitimate Argentine court documents, such as preventive detention review documents, to enhance credibility and facilitate malware delivery.
Initial Vector: Spear-phishing emails containing a ZIP archive with three components: a malicious LNK file, a BAT-based loader script, and a judicial PDF decoy. Stage 1: The LNK file executes PowerShell with execution policy bypass and hidden window mode, disguising it as a legitimate document. Stage 2: The BAT loader connects to GitHub repositories to download the second-stage payload, using spoofed User-Agent strings. Stage 3: Deploys the primary RAT component, performing anti-analysis checks and establishing communication with a command and control (C2) server.
The decoy document appears as an Argentine federal court resolution, complete with case numbers, judicial signatures, and procedural language. Its structure closely mirrors authentic court rulings to increase the likelihood of user interaction.
Command Set: Includes commands for persistence, file operations, credential theft, ransomware functionality, and privilege escalation. Persistence Techniques: Utilizes registry Run keys and scheduled tasks with randomized names to maintain access. Anti-Analysis Checks: Detects virtual machines, sandbox environments, and debuggers.
Organizations are advised to implement enhanced email filtering, disable LNK file execution from email sources, enforce PowerShell execution policies, and deploy endpoint detection and response solutions to identify suspicious process chains and C2 communications patterns.
Seqrite Labs has identified a spear-phishing campaign targeting the judicial sector in Argentina, utilizing a Rust-based Remote Access Trojan (RAT).
Hash Name / File Path C2 Server
dc802b8c117a48520a01c98c6c9587b5 info/juicio-grunt-posting.pdf.lnk
45f2a677b3bf994a8f771e611bb29f4f D:\auto_black_abuse\resources\unzipped\20251215_140518_2025-11-28\13adde53bd767d17108786bcc1bc0707c2411a40f11d67dfa9ba1a2c62cc5cf3.zip
02f85c386f67fac09629ebe5684f7fa0 info/health-check.bat
976b6fce10456f0be6409ff724d7933b \msedge_proxy.exe
233a9dbcfe4ae348c0c7f4c2defd1ea5 info/notas.pdf
— — 181.231.253.69:4444
Based on reporting by GBHackers.
