Gennaio 26, 2023
Remcos RAT, a remote control tool, has gained popularity among cybercriminals since its debut in 2018. It is sold commercially on underground forums and markets. The tool allows complete control over targeted machines and has been used in several high-profile attacks. Recently, attack campaigns have been observed using Microsoft OneNote attachments and documents to deliver the Remcos RAT. These attachments are delivered through phishing emails and malicious links to open repositories like Dropbox and OneDrive. Though OneNote does not support traditional macros, malicious attachments can be embedded in OneNote notebooks and launched on victims’ machines. This video shows how a malicious document hosted on Dropbox is installed to install Remcos RAT and how SentinelOne Singularity can prevent this malicious behavior. The SentinelOne platform detects and blocks these types of threats by analyzing the behavior of files and processes on a device. If it detects any suspicious activity, it can immediately take action to block the malware and prevent it from spreading.
SentinelOne PartnerOne - America's 2025
⛳️ Last week in Pebble Beach the America's best cybersecurity partners came together for our annual PartnerOne summit. Check out…
Just a Sec: Cybersecurity Unfiltered—Fast, Frank, and From the Front Lines
Welcome to the first-ever Just A Sec, a no-holds-barred, quick-fire monthly livestream. It’s cybersecurity like you’ve never heard it before—unfiltered,…
Scopri cosa può fare la nostra piattaforma di sicurezza informatica autonoma intelligente per proteggere la tua azienda oggi e domani.