PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN Apps

A new malware called PLAYFULGHOST, with information-gathering features similar to Gh0st RAT, is being distributed through phishing emails and SEO poisoning. PLAYFULGHOST uses various techniques to gain persistence and steal data, including keylogging, screen capture, and file transfer. The targeting of specific applications and VPN lures suggests a focus on Chinese-speaking Windows users.

*****
Written on