• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Microsoft issues StrRAT warning, don’t open PDF files from unknown sources at will

Microsoft issues StrRAT warning, don’t open PDF files from unknown sources at will

Claire by Claire
May 26, 2021 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

In the past, malware disguised as Word macros and downloaded files frequently appeared, but are innocent-looking pure files necessarily safe? Microsoft’s security intelligence team recently discovered that a new type of malware is spread through PDF attachments, a well-known text file. We would like to remind everyone not to open email attachments from unknown sources or that are not trustworthy.

Microsoft issues StrRAT warning, don’t open PDF files from unknown sources at will

The Microsoft Security Intelligence Team recently posted on Twitter that it discovered that the latest version of StrRAT malware (1.5) written in JAVA appeared in a large-scale email distribution last week in the form of a PDF attachment included in the email. StrRAT is a Trojan that allows malicious people to remotely access infected people. It can be used to steal users’ passwords and credentials, and control user systems. Researchers also found that this malware can disguise itself as ransomware to confuse the public.

The latest version of the Java-based STRRAT malware (1.5) was seen being distributed in a massive email campaign last week. This RAT is infamous for its ransomware-like behavior of appending the file name extension .crimson to files without actually encrypting them. pic.twitter.com/mGow2sJupN

— Microsoft Security Intelligence (@MsftSecIntel) May 19, 2021


In a post about the malware, Microsoft stated that once your system is infected by the virus, StrRAT will automatically connect to the C2 server. The new version 1.5 is obviously more obscure and modular than the past version, but generally speaking, the function of opening a backdoor in the system still exists to collect browser passwords, run remote commands and PowerShell, and record keyboard input processes. This malicious activity was mainly spread through email, and the email strongly encouraged users to click on an attachment that looked like a PDF file, but in fact it contained malware.

Microsoft 365 Defender delivers coordinated defense against this threat. Machine learning-based protections detect and block the malware on endpoints, and this signal informs Microsoft Defender for Office 365 protections against malicious emails.

— Microsoft Security Intelligence (@MsftSecIntel) May 19, 2021


Microsoft noted that its Microsoft 365 Defender can already protect systems from StrRAT, and machine learning-based protection can also detect and block malware on computers. Therefore, the author would like to remind everyone that although each system update is annoying and time-consuming, there may be bugs. But more importantly, in the update file, the system vendor will also include recently discovered security vulnerabilities and the latest security hazard protection. Therefore, it is still necessary to keep the system at the latest version at all times. Don’t be afraid of trouble or laziness, which will allow malicious people to take advantage of it.

Source: KOCPC Chinese

Tags: appendixe-mailInternet securitymalwareMicrosoftPDFTrojan horseVirus

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology