The new remote access trojan (RAT), ResolverRAT, is being used globally against organizations, particularly the healthcare and pharmaceutical sectors. It is being spreading through phishing emails tailored to the target’s language, disguised as legal or copyright violation claims. The malware, which was discovered by Morphisec, runs entirely in memory, making detection and analysis difficult. It also uses a complex state machine for obfuscation, fingerprinting resource requests to detect sandboxing tools.

AI is rewriting the ransomware playbook – can businesses keep up?
AI is making ransomware threats more accessible and sophisticated, warn cybersecurity experts. Criminal gangs are using AI to launch highly targeted attacks with greater speed