In the past, malware disguised as Word macros and downloaded files frequently appeared, but are innocent-looking pure files necessarily safe? Microsoft’s security intelligence team recently discovered that a new type of malware is spread through PDF attachments, a well-known text file. We would like to remind everyone not to open email attachments from unknown sources or that are not trustworthy.

Microsoft issues StrRAT warning, don’t open PDF files from unknown sources at will
The Microsoft Security Intelligence Team recently posted on Twitter that it discovered that the latest version of StrRAT malware (1.5) written in JAVA appeared in a large-scale email distribution last week in the form of a PDF attachment included in the email. StrRAT is a Trojan that allows malicious people to remotely access infected people. It can be used to steal users’ passwords and credentials, and control user systems. Researchers also found that this malware can disguise itself as ransomware to confuse the public.
The latest version of the Java-based STRRAT malware (1.5) was seen being distributed in a massive email campaign last week. This RAT is infamous for its ransomware-like behavior of appending the file name extension .crimson to files without actually encrypting them. pic.twitter.com/mGow2sJupN
— Microsoft Security Intelligence (@MsftSecIntel) May 19, 2021

In a post about the malware, Microsoft stated that once your system is infected by the virus, StrRAT will automatically connect to the C2 server. The new version 1.5 is obviously more obscure and modular than the past version, but generally speaking, the function of opening a backdoor in the system still exists to collect browser passwords, run remote commands and PowerShell, and record keyboard input processes. This malicious activity was mainly spread through email, and the email strongly encouraged users to click on an attachment that looked like a PDF file, but in fact it contained malware.
Microsoft 365 Defender delivers coordinated defense against this threat. Machine learning-based protections detect and block the malware on endpoints, and this signal informs Microsoft Defender for Office 365 protections against malicious emails.
— Microsoft Security Intelligence (@MsftSecIntel) May 19, 2021
Microsoft noted that its Microsoft 365 Defender can already protect systems from StrRAT, and machine learning-based protection can also detect and block malware on computers. Therefore, the author would like to remind everyone that although each system update is annoying and time-consuming, there may be bugs. But more importantly, in the update file, the system vendor will also include recently discovered security vulnerabilities and the latest security hazard protection. Therefore, it is still necessary to keep the system at the latest version at all times. Don’t be afraid of trouble or laziness, which will allow malicious people to take advantage of it.
Source: KOCPC Chinese