FOLLOW US

Thu

June 4, 2026

Science & Technology May 14, 2021 3 mins read

New RevengeRat Malware steals passwords, browser data

Science & Technology ı By Jackie Allen

0 Comments

phishing revenge rat

Security news Threat Post, says that Microsoft has issued an alert. The warning is of a remote access trojan (RAT) that targets the aviation and travel industry. The new RevengeRAT malware campaign can harvest screenshots, keystrokes, webcam feeds, credentials, and browser data.

Microsoft published information on GitHub that security teams can use if they detect these threats on their network. And the latest Microsoft Security Intelligence details how phishing emails are used to upload RevengeRAT. 

Snip3 Crypter 

Morphisec the software security company dubbed the crypter service "Snip3." The name comes from a username taken from the malware found across earlier variants. 

This is a highly sophisticated Crypter-as-a-Service. And it delivers numerous RAT families onto a variety of target machines.

The malware or "payload" is most commonly delivered by disguising phishing emails. If the target clicks on an image on the email, Snip3 delivers its payload via some form of a malicious VBScript. Snip3 in turn conveys strains of the RAT payloads (RevengeRAT or AsyncRAT).

Using phishing emails to deliver RevengeRAT

Phishing emails usually contain a link to an image disguised as a PDF file. The emails usually evade security filters since the embedded link is generated with a legitimate web service.

"The campaign uses emails that spoof legitimate organizations, with lures relevant to aviation, travel, or cargo. An image posing as a PDF file contains an embedded link (typically abusing legitimate web services) that downloads a malicious VBScript, which drops the RAT payloads," Microsoft said. 

 

 

Once the RATs are active, they directly connect to a command and control (C2) server. And then proceed to download more malware from paste sites like pastebin.com. 

"The RATs connect to a C2 server hosted on a dynamic hosting site to register with the attackers, and then uses a UTF-8-encoded PowerShell and fileless techniques to download three additional stages from pastebin[.]com or similar sites," reports Microsoft Security Intelligence. 

Sophisticated Phishing

Roger Grimes, tech evangelist at KnowBe4, comments on the RevengeRAT campaign. Grimes says that this type of campaign shows a new development in malware gang activity. And by specializing in attacking specific vertical sectors besides the usual, financial and government RevengeRat differs. They use precise lures in phishing emails. And the campaigns are tailored to a more directed attack.

12

Previous Article

Elon Musk’s Tesla Suspends accepting Payments in Bitcoin, Considers Dogecoin Instead

Read More
Jackie Allen
3155 Posts

Jackie Allen

Jackie is a freelance journalist and technology geek. She worked as a telecom project director for AT&T and BellSouth. Before joining the USA Herald she has written books, articles, blogs and whitepapers. Her clients include Samsung and other technology companies.

Discussion

No comments yet. Be the first to join the discussion!

Don’t Miss It
Arizona January 11, 2025
Kelly Warner Law Firm Blames USA…

In what appears as a desperate attempt to defend multiple…

By – USA Herald
Arizona January 4, 2025
Aaron Kelly Law Firm Resorts To…

Attorney Aaron Kelly and his law partner Daniel Warner are…

By – Jeff Watterson
Arizona December 12, 2024
Arizona Bar Opens Investigation on Attorney…

USA Herald recently reported on a developing story involving Attorneys…

By – Paul O'Neal
America June 2, 2026
Josh Duggar Appeal Denied as Convicted…

Josh Duggar remains behind bars after a federal judge denied…

By – Jackie Allen
America June 2, 2026
Federal Judge Lets ’86 47′ Flag…

An Obama-appointed judge just ruled a political group can keep…

By – Samuel Lopez
California News June 2, 2026
Sabrina Carpenter Granted Restraining Order Following…

Citing “severe emotional distress,” the American pop star has successfully…

By – Tyler Brooks
Entertainment June 2, 2026
The Diddy Fallout: Cassie Fights Back…

As Sean “Diddy” Combs serves time behind bars, the shockwaves…

By – Tyler Brooks
America June 2, 2026
South Carolina Jury Clears Store Owner…

A South Carolina courtroom erupted with emotion Monday after a…

By – Tyler Brooks
Business June 2, 2026
Archer Aviation: The eVTOL Takeoff Facing…

Strategic Analysis — June 2026 The electric vertical takeoff and…

By – Tyler Brooks
America June 1, 2026
Sleeping Dog Documentary Chronicles Jeremy Corbell’s…

The new documentary Sleeping Dog arrives at a pivotal moment…

By – Jackie Allen
America June 1, 2026
Kendall Jenner, Jacob Elordi and the…

I’ve been writing about royals and celebrities for 20 years.…

By – Nathan Kay
America June 1, 2026
Chaotic Midnight Shooting Leaves 3 Bloodied…

Downtown San Jose gunfire wounds 3, sparks wild building crash…

By – Tyler Brooks
America June 1, 2026
43-year-old Man Hospitalized After a Stranger…

Stranger shoots San Antonio man, 43, through door By Tyler…

By – Tyler Brooks
America June 1, 2026
Hurricane Season Starts Today – Here’s…

Texas faces 20% hurricane risk as season begins By Tyler…

By – Tyler Brooks
America June 1, 2026
U.S. Military Strike In The Eastern…

U.S. Pacific boat strike kills 3, casualties cross 200 By…

By – Tyler Brooks
America June 1, 2026
Rare Blue Micromoon Lights Up the…

Skywatchers are in for a unique celestial event as a…

By – Jackie Allen
America May 31, 2026
Murder-for-hire Ends with Life Sentence for…

A shocking Murder-for-hire case that spanned multiple states has concluded…

By – Jackie Allen
America May 31, 2026
Frank Lloyd Wright and the Taliesin…

In The Killer and Frank Lloyd Wright, veteran true-crime author…

By – Jackie Allen
America May 30, 2026
Hollywood at a Crossroads: Spencer Pratt…

Los Angeles has its primary election this Tuesday, and the…

By – Jackie Allen
America May 30, 2026
Hayden Panettiere has a Memoir About…

Hayden Panettiere is revealing the emotional toll of growing up…

By – Jackie Allen
America May 29, 2026
Blue Origin Rocket Explodes in Massive…

Blue Origin suffered a major setback Thursday night when one…

By – Jackie Allen
America May 29, 2026
Blue Origin Rocket Explodes in Massive…

Blue Origin suffered a major setback Thursday night when one…

By – Jackie Allen
America May 28, 2026
Alien Coneheads: New DNA Study Doesn’t…

The mystery surrounding the so-called Alien Coneheads of Peru has…

By – Jackie Allen
America May 28, 2026
Trump’s Alien.gov Reveal Turns Into Immigration…

INSIDE THIS REPORT What millions thought would be a historic…

By – Samuel Lopez
America May 28, 2026
Trump’s UFO files reveal mysterious flying…

The newly released UFO Files from the Trump administration have…

By – Jackie Allen
America May 28, 2026
Who’s Lying? E. Jean Carroll Faces…

Author and columnist E. Jean Carroll is once again at…

By – Jackie Allen
America May 28, 2026
Super El Niño: Will 2026 be…

Scientists across the globe are increasingly warning that a potential…

By – Jackie Allen
Business June 2, 2026
Archer Aviation: The eVTOL Takeoff Facing…

Strategic Analysis — June 2026 The electric vertical takeoff and…

By – Tyler Brooks
Featured June 2, 2026
From a Casual Night Out to…

It Doesn’t Happen Here’: Quiet Suburb Left Shattered After Fatal…

By – Tyler Brooks
Business June 2, 2026
From Folklore to High Finance: The…

Wall Street and Global Powers Monetize UFO Craze By Tyler…

By – Tyler Brooks
Business June 2, 2026
Anthropic Files Historic IPO Triggering Fierce…

Anthropic Files Historic IPO Triggering Fierce Wall Street Ethics War…

By – Tyler Brooks
Florida News June 1, 2026
Manhunt underway for Florida felon Adriel…

Manhunt underway for Florida felon Adriel Martinez after release breach…

By – Tyler Brooks
Featured June 1, 2026
Hawaii Warns Communities of Impending Kilauea…

Hawaii Warns Communities of Impending Kilauea Ashfall By Tyler Brooks…

By – Tyler Brooks
Health June 1, 2026
New Pill Doubles Survival for Pancreatic…

Pancreatic cancer pill doubles life to 13 months By Tyler…

By – Tyler Brooks
California News May 31, 2026
FDA warns public as cookie firm…

FDA warns public as cookie firm rejects urgent recall request…

By – Tyler Brooks
Health May 31, 2026
Trump orders CDC to slash childhood…

Trump orders CDC to slash childhood vaccines from 17 to…

By – Tyler Brooks
Health May 30, 2026
USDA warns Americans over Salmonella in…

USDA warns Americans over Salmonella in meat products By Tylor…

By – Tyler Brooks
America May 28, 2026
GKN Aerospace’s Biggest Battle May Not…

By Samuel López | USA Herald The immediate danger of…

By – Samuel Lopez
America May 24, 2026
Garden Grove Chemical Crisis Sparks Class…

By Samuel López | USA Herald A full-scale legal and…

By – Samuel Lopez
Featured June 1, 2026
Wembanyama in Tears: Spurs Dethrone Thunder…

Spurs dethrone Thunder in epic Game 7 road victory By…

By – Tyler Brooks
High Profile Court Cases May 31, 2026
Supreme Court signals 27 states could…

Supreme Court signals 27 states could ban trans female athletes…

By – Tyler Brooks
Sports May 31, 2026
Mauricio Pochettino sounds alarm on Chris…

Mauricio Pochettino sounds alarm on Chris Richards injury By Tylor…

By – Tyler Brooks
International May 30, 2026
USMNT star Chris Richards tears two…

USMNT star Chris Richards tears two ankle ligaments By Tylor…

By – Tyler Brooks
America May 28, 2026
“Money” Mayweather Tucks Tail: $100 Million…

Floyd Mayweather has beaten every opponent who ever climbed into…

By – Samuel Lopez
America May 27, 2026
Mackenzie Shirilla Sent Text Messages to…

Mackenzie Shirilla is once again at the center of public…

By – Jackie Allen

No posts found.

No posts found.

Signup for the USA Herald
exclusive Newsletter