HomeSecurityMulti-stage Phishing Campaign Targets Russia with Amnesia RAT

Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

A new multi-stage phishing campaign has been spotted targeting users in Russia with ransomware and a remote access Trojan called Amnesia RAT.

See also: Pulsar RAT: Execution in memory & HVNC for invisible access to systems

Amnesia RAT
Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

The attack begins with social engineering bait delivered via business-themed documents, which are designed to appear innocent. These documents and accompanying scripts act as visual distractions, distracting victims to fake tasks or status messages, while the malicious activity runs silently in the background.

The Amnesia RAT campaign stands out for two reasons. First, it uses multiple public cloud services to distribute different types of payloads. While GitHub is primarily used to distribute scripts, binary payloads are placed on Dropbox. This separation complicates removal efforts, significantly improving resilience.

Another feature of the campaign is the functional abuse of defendnot to disable Microsoft Defender. Defendnot was released last year by a security researcher who goes by the alias es3n1nas a way to trick the security program into believing that another antivirus product is already installed on the Windows host.

The campaign leverages social engineering to distribute compressed files, which contain multiple decoy documents and a malicious Windows shortcut (LNK) with Russian-language filenames. The LNK file uses a double extension (“Задание_для_бухгалтера_02отдела.txt.lnk”) to give the impression that it is a text file.

When executed, it runs a PowerShell command to retrieve the next stage of the PowerShell script hosted in a GitHub repository, which then acts as a first-stage loader to establish an access point, prepare the system to hide evidence of malicious activity, and hand over control flow to subsequent stages.

The script first suppresses visible execution by programmatically hiding the PowerShell console window, removing any immediate visual cues that a script is being executed. It then creates a decoy document in the user's local application data directory. Once written to disk, the decoy document is automatically opened.

See also: SHADOW#REACTOR: New campaign distributes Remcos RAT

Multi-stage Phishing Campaign Targets Russia with Amnesia RAT
Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

Once the document is displayed to the victim to perpetuate the scam, the script sends a message to the attacker using the Telegram Bot API, informing the operator that the first stage has been successfully executed. After a deliberately inserted delay of 444 seconds, the PowerShell script executes a Visual Basic Script hosted in the same repository location.

This offers two critical advantages: it keeps the payload lightweight and allows attackers to update or replace the payload's functionality in real time without having to introduce changes to the attack chain.

The Visual Basic Script is particularly obfuscated and acts as a controller that assembles the next stage of the payload directly in memory, thus avoiding leaving any traces on disk. The final stage of the script checks if it is running with elevated privileges and, if not, repeatedly displays a User Account Control (UAC) to force the victim to grant it the necessary permissions.

The script pauses for 3,000 milliseconds between attempts.

In the next phase, the Amnesia RAT initiates a series of actions to suppress visibility, neutralize endpoint protection mechanisms, conduct reconnaissance, prevent recovery, and finally deploy the main payloads:

– Configures exceptions in Microsoft Defender to prevent the program from scanning ProgramData, Program Files, the desktop, downloads, and the system temporary directory.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– Uses PowerShell to disable additional Defender protections.

– Deploys defendnot to register a fake antivirus product with the Windows security environment and cause Microsoft Defender to be disabled to avoid potential conflicts.

See also: Transparent Tribe: New RAT attacks against the Indian Government

Multi-stage Phishing Campaign Targets Russia with Amnesia RAT
Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

– Conducts environmental reconnaissance and surveillance through screenshot capture.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS