Threat researchers reported that the Water Basilisk campaign used a new HCrypt 7.8 variant to distribute multiple remote access trojans through phishing emails and phishing websites. The intrusion chain began with malicious ISO files carrying obfuscated VBScript stagers, then moved through in-memory VBScript and PowerShell stages that established persistence, deobfuscated payloads, and injected malware into legitimate processes to avoid detection.
The final-stage loader was capable of deploying as many as seven RAT families, including NjRat, BitRAT, NanoCore RAT, QuasarRAT, LimeRAT, and Warzone RAT, while researchers also observed cryptocurrency clipboard hijacker binaries generated through HCrypt. The operation relied on public file-hosting services such as archive.org, transfer.sh, and discord.com to host malware components, and used compromised WordPress sites for phishing kits; researchers said the activity underscored HCrypt's role as an actively developed crypter-as-a-service whose operators appeared to profit both from builder sales and built-in hijacker functionality.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that the fileless Water Basilisk campaign reached peak activity in mid-August 2021, using phishing emails and phishing websites to deliver malicious ISO files. The attack chain used a new HCrypt 7.8 variant and could deploy multiple RAT families including NjRat, BitRAT, NanoCore RAT, QuasarRAT, LimeRAT, and Warzone RAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.