⚠️ New DeedRAT Backdoor Alert:
Chinese hackers are using phishing emails to drop a modular backdoor called DeedRAT via DLL side‑loading of a legitimate VIPRE AV binary, MambaSafeModeUI.exe
• Installs from ZIP containing signed binary, malicious DLL & encrypted payload
• Achieves stealth: in‑memory shellcode, service persistence, mutex protection
• Communicates via TCP (ports 80/443) to C2 at luckybear669.kozow[.]com
• New “NetAgent” plugin adds multithreaded C2 handling
• Enhanced obfuscation: API hashing, junk code, custom LCG encryption (replacing RC4)