<\/a><\/figure>\n\n\n\n<\/gwmw><\/p>\n\n\n\n
The Insikt Group also spotted a website distributing AMOS malware along with Rhadamanthys by posing as legitimate software. Instead of hosting the malware directly, the fake application site redirects users to file-sharing services like Dropbox and Bitbucket. One of these malicious sites masqueraded as Rainway, a now-defunct remote desktop video game streaming service. While Rainway\u2019s legitimate domain is rainway[.]com, the malicious domain is rainway[.]cloud. The researchers noticed that Google search for “Rainway” currently lists rainway[.]cloud as a top result above the legitimate rainway[.]com.<\/p>\n\n\n\n
The report includes IndicatorsofCompromise and mitigations for this campaign.<\/p>\n\n\n\n
<\/p>\n\n\n\n