Security researchers have identified a new campaign targeting financial institutions and government organizations with a customized version of a remote access tool called “Proyecto RAT.”
The payload uses Yopmail, the disposable email service, for C&C communication. Yopmail is known for creating temporary inboxes.

Infection process
According to the Trend Micro report, the attack primarily targets organizations in the South American region, particularly Colombia. The infection begins with a customized email sent to the target from open or compromised mail servers in the South American region.
The email contains an RTF attachment file and a tempting message to grab users' attention.
The attachment contains shortened links that direct victims to file sharing services. The delivery file is a macro-enabled MHTML file. The macrocode is responsible for downloading and executing the payload, the Immediate Monitor RAT.

The Monitor RAT monitors all network activities and includes information about the execution of the second stage of the payload. The Imminent Monitor RAT supports a wide range of monitoring activities including logging , file transfers, screenshot capture, and audio recording.
The second stage of the payload is “Proyecto RAT” which uses the yopmail email service for C&C communication.
The malware connects to a mailbox, reads the only available email message, parses it, and then extracts the email subject.
Researchers believe that “Proyecto RAT” is either an old and limited version of Xpert RAT, a customized modification of Xpert RAT, or malware with source code based on Xpert RAT.

