Bunk-bed.7z Info
: The archive usually contains three main components:
: A modular Remote Access Trojan (RAT) known for its use by various APT groups. Bunk-Bed.7z
: Look for unusual entries in Task Scheduler or Startup folders that may have been created during the infection. : The archive usually contains three main components:
: An open-source RAT used by cybercriminals for remote control and data theft. : The shortcut runs the legitimate executable, which
: The shortcut runs the legitimate executable, which unknowingly loads the malicious DLL ( DLL Sideloading ). This DLL then decrypts and runs the final payload in memory to avoid detection by traditional antivirus. Associated Malware Families
: If you have already executed a file from this archive, disconnect the device from the internet to prevent data exfiltration.
: Inside the archive, there is typically a malicious Windows Shortcut ( .lnk ). When a user double-clicks it, it executes a hidden command (often using cmd.exe or powershell.exe ).