Researchers reported that malicious email attachments disguised as JavaScript files were being used to deliver a broad set of remote access Trojans and stealers through heavily obfuscated loader chains. HP Wolf Security identified the activity as RATDispenser, a stealthy JavaScript loader that decodes itself, launches cmd.exe, writes a VBScript file into %TEMP%, and then either drops or downloads a second-stage payload. Analysis of 155 samples found that 94% acted as droppers rather than network downloaders, with STRRAT and WSHRAT making up 81% of observed payloads; other delivered malware included Formbook, Remcos, AdWind, Panda Stealer, GuLoader, and Ratty. The campaign’s low average detection rate and layered obfuscation indicated an effective distribution mechanism for commodity malware.
Separate analysis of a phishing campaign targeting European organizations showed a similar JavaScript-to-VBS infection pattern delivering H-Worm/Houdini after emails impersonating entities such as UNWTO and IATA. Lab52 attributed that operation to LazyScripter and found that the attackers’ obfuscated scripts had themselves been tampered with by the online service hackfree.org, which injected an additional njRAT downloader, creating a double-compromise scenario. Researchers linked the primary campaign to infrastructure including stub.ignorelist.com and securessl.fit, while the injected secondary activity used a PowerShell downloader that contacted 185.81.157.186 to retrieve content from /NDA/199.png, underscoring how obfuscated JavaScript loaders were being reused to distribute multiple RAT families through phishing.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The domain securessl.fit, used in the phishing operation and linked from the fake job-offer PDF, was registered on July 17, 2021. It resolved to 192.64.119.125 and redirected through a DuckDNS domain.
In July 2021, a phishing campaign attributed to the emerging APT group LazyScripter targeted important European entities using lures impersonating organizations including UNWTO and IATA. The emails delivered compressed archives containing a benign PDF and obfuscated JavaScript files.
HP reported that RATDispenser, an evasive JavaScript loader spread through malicious email attachments, was used during 2021 to deliver eight malware families including STRRAT, WSHRAT/Houdini, AdWind, Formbook, Remcos, Panda Stealer, GuLoader, and Ratty. STRRAT and WSHRAT accounted for 81% of observed payloads.
Using a YARA rule named js_RATDispenser, researchers conducted a three-month retrohunt and identified 155 RATDispenser samples across three variants. Their analysis found 94% of the samples were droppers rather than network downloaders.
Researchers tested the online obfuscation service hackfree.org and found it injected its own malware into every obfuscated script it produced. In the analyzed LazyScripter samples, this added a second compromise path via an njRAT downloader distinct from the H-Worm/Houdini payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcelab52.io
Open sourcethreatresearch.ext.hp.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.