Skip to content

Malware

RMOT

According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS.

RMOT is a PowerShell malware family operated by DarkHotel.

Background

Trellix describes this as a first-stage, PowerShell-based malware delivered through Excel/VBS. It can gain an initial foothold and exfiltrate data, and among the observed targets are hotels in Macao.


Source: Malpedia (Fraunhofer FKIE).