Malware XMRig OrcusRAT etc disguised as MS Office crack
The report details an ongoing malware campaign targeting South Korean users which disguises malicious payloads as cracked versions of Microsoft Office and other popular software. The attackers are distributing a variety of malware including downloaders coin miners remote access tools (RATs) proxies and anti-antivirus components. These are installed persistently through scheduled tasks and utilise encoded PowerShell commands for updates. The primary malware families identified include Orcus RAT for system control XMRig cryptominer 3Proxy for creating a proxy network and components to evade security products.