The new remote access trojan (RAT), ResolverRAT, is being used globally against organizations, particularly the healthcare and pharmaceutical sectors. It is being spreading through phishing emails tailored to the target’s language, disguised as legal or copyright violation claims. The malware, which was discovered by Morphisec, runs entirely in memory, making detection and analysis difficult. It also uses a complex state machine for obfuscation, fingerprinting resource requests to detect sandboxing tools.

New ResolverRAT malware targets healthcare and pharma orgs worldwide
Security researchers have identified a new malware, ResolverRAT, used in attacks on the healthcare and pharmaceutical sectors. Distributed via phishing emails with malicious attachments, ResolverRAT