Phishing Archives Now Install Persistent Keyloggers

A mail attachment can now carry the whole attack chain. The trap is not a document macro or a software bug. It is a RAR file that launches scripts, unpacks more scripts, and ends with a persistent VIPKeylogger install on the endpoint. SANS says the wave starts with a fake bank email and a RAR archive that holds a VBS script. That script decodes data, uses PowerShell to unpack more files, drops an AutoIt interpreter and script, and adds a Run key for persistence. The report includes hashes and a network indicator tied to cphost17.qhoster.net. The practical change is that simple attachment blocking is not enough. By the time PowerShell appears, the payload has already been staged and set to survive reboot, which makes these archives a direct path to credential theft on Windows endpoints.

Sources