IronHusky updates the forgotten MysterySnail RAT to target Russia and Mongolia
SecureList
APRIL 17, 2025
This file is encrypted with a single-byte XOR and is loaded at runtime. Its malicious DLL, which is deployed by the intermediary backdoor, is designed to load a payload encrypted with RC4 and XOR, and stored inside a file named attach.dat. Allows reading files, managing services, and spawning new processes.
Let's personalize your content