VCURMS is a Java-based remote access trojan used in phishing campaigns that deliver a malicious downloader and then deploy additional Java payloads. It has been observed alongside STRRAT in payment-themed lures, with payload staging on public cloud and code-hosting services and multiple layers of obfuscation and commercial protection to hinder detection and analysis. The malware is notable for using email-based command and control, including Proton Mail, rather than a conventional interactive C2 channel.
On Windows systems, VCURMS establishes persistence through the Startup folder. It identifies infected hosts using system-specific information and processes inbound email messages to locate commands intended for a particular victim. Supported operator actions include collecting host details, executing shell commands, uploading and downloading files, and searching the filesystem. VCURMS can also retrieve and launch secondary components, including a keylogger and an infostealer.
The associated infostealer functionality targets browser and application data, including cookies, saved credentials, autofill data, browsing history, and account information from platforms such as Discord and Steam. Observed browser targeting includes Chromium- and Firefox-based browsers. The keylogging component records keystrokes, while exfiltration of collected data is coordinated through the main VCURMS component. The malware has been reported as sharing similarities with Rude Stealer while operating under the VCURMS name.
VCURMS primarily affects environments where Java execution is available, and the observed intrusion chain used phishing to initiate infection. Its combination of Java portability, layered obfuscation, email-driven C2, persistence, remote command execution, file transfer, keylogging, and information theft makes it a flexible post-compromise RAT suited for credential and data theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Recently, FortiGuard Labs uncovered a phishing campaign that entices users to download a malicious Java downloader with the intention of spreading new VCURMS and STRRAT remote access trojans (RAT).
The phishing email shown in Figure 2 is part of this attack campaign. It targets staff members, implying that a payment is underway and encourages them to click a button to verify payment information. Upon clicking the button, a harmful JAR file hosted on AWS is downloaded to the victim's computer.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VCURMS is a Java-based remote access trojan (RAT) distributed via phishing, notable for using Proton Mail addresses for C2 communication.
A newly observed Java-based remote access trojan that uses email for command-and-control, persists via the Startup folder, identifies victims by computer name and volume ID, executes shell commands, uploads/downloads files, searches for files, and deploys secondary credential theft and keylogging components. It also includes a modified infostealing component that collects browser data, app account data, system information, screenshots, and sends stolen data back via email.
VCURMS is a remote access trojan (RAT) delivered via phishing campaigns, capable of establishing communication with a command-and-control server and providing remote access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.