The Horus Protector crypter uses a new delivery technique that makes detection more difficult due to its obfuscation tactics. It uses VBE scripts to distribute malware such as AgentTesla, Remcos, Snake, NjRat, among others. The method involves encoding and storing malicious files in registry locations before they’re executed. Notably, the execution process involves a check on the status of Windows Defender – the script terminates if Defender is active.

ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More
The online world is changing fast. Every week, new scams, hacks, and tricks show how easy it’s become to turn everyday technology into a weapon.