Key Takeaways The intrusion began with a Lunar Spider linked JavaScript file disguised as a tax form that downloaded and executed Brute Ratel via a MSI installer. Multiple types of malware were dep…| The DFIR Report
Explore the resumed activity conducted by Latrodectus download and executed by BRC4 post Operation Endgame| RevEng.AI Blog
Extracting new AES encrypted strings from this RAT| OALABS Research