New Modular RAT Steals Credentials and Captures Screenshots

A highly sophisticated spearphishing campaign dubbed “Operation GriefLure.” The attackers targeted senior executives at Viettel Group, Vietnam’s largest telecommunications provider, and St. Luke’s Medical Center in the Philippines.

What makes this campaign uniquely devastating is its use of perfectly authentic, legally sensitive documents as decoys.

Instead of forging files, the threat actors harvested real legal disputes from social media, weaponizing a genuine data breach victim’s distress to create a lure that easily bypasses basic security awareness training.

For the Philippine target, the attackers crafted a highly convincing whistleblower complaint alleging financial fraud to trigger immediate action from hospital administrators.

Modular RAT Steals Credentials

The attack begins when victims download a double-compressed RAR or ZIP archive containing a malicious Windows shortcut (LNK) file disguised alongside the decoy PDFs.

Once executed, the LNK file uses a Living-off-the-Land (LotL) technique by abusing the native Windows ftp.exe binary.

This stealthy approach allows the malware to bypass conventional endpoint detection by silently assembling a payload from disguised document fragments in the background.

Modular RAT Steals Credentials (Source: seqrite)
Modular RAT Steals Credentials (Source: seqrite)

The entire compromise happens invisibly in under ten seconds, all while the victim views the legitimate decoy document.

At the core of this operation is a custom execution framework, sfsvc.exe, which is a heavily modified version of the legitimate Windows registration tool.

Modular RAT Steals Credentials (Source: seqrite)
Modular RAT Steals Credentials (Source: seqrite)

This framework loads a polymorphic loader called 360.dll. Through fileless execution and process injection, the malware forcibly terminates and replaces the Windows Explorer process, injecting its malicious shellcode into a trusted system environment.

Once active, the modular Remote Access Trojan (RAT) deploys a wide array of surveillance capabilities.

Modular RAT Steals Credentials (Source: seqrite)
Modular RAT Steals Credentials (Source: seqrite)

It systematically captures screenshots of the victim’s desktop, dynamically adjusting image resolution based on network conditions, and exfiltrates them to a remote server.

Furthermore, the malware includes a highly targeted credential-harvesting module.

It scours the infected system for sensitive data stored in web browsers like Chrome, FTP clients like FileZilla, remote access tools like Sunlogin, and communication applications such as WeChat.

According to Seqrite research, security researchers assess with moderate-to-high confidence that Operation GriefLure is the work of a China-nexus threat cluster.

This attribution is supported by several technical artifacts, including the use of Hong Kong-based bulletproof hosting, specifically Kaopu Cloud, which has a documented history of supporting Asia-Pacific threat actors.

Indicators of Compromise

File Name / TypeIndicator (SHA256 / Domain)
HỒ SƠ BẰNG CHỨNG GHI NHẬN CHUỖI HÀNH VI VI PHẠM PHÁP LUẬT CÓ HỆ THỐNG VÀ LEO THANG CỦA TẬP ĐOÀN VIETTEL.lnk35af2cf5494181920b8624c7b719d39590e2a5ff5eaa1a2fa1ba86b2b5aa9b43
Whistleblowing_Report_SLMC_Fraud_and_Misconduct_2026.pdf.lnkbc090d75f51c293d916c40d4b21094faaec191a42d97448c92d264875bf1f17b
Valid_Government_Identification_Card_of_Dela_Cruz_Juan_-_Philippine_National_ID_Front_Side.png.lnk197f11a7b0003aa7da58a3302cfa2a96a670de91d39ddebc7a51ac1d9404a7e6
iPad_Pro_Display_Spec_Final_CONFIDENTIAL.docx.lnkf34f550147c2792c1ff2a003d15be89e5573f0896c5aa6126068baa4621ef416

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories