{"id":4263,"date":"2022-09-09T11:06:31","date_gmt":"2022-09-09T16:06:31","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4263"},"modified":"2022-09-09T11:06:31","modified_gmt":"2022-09-09T16:06:31","slug":"escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/","title":{"rendered":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code"},"content":{"rendered":"<p>A new remote administration tool (RAT) that uses Microsoft Office and Adobe PDF documents to deliver malicious code has been spotted on dark web forums and Telegram channels called Escanor in an advisory published on Sunday, August 21, 2022.<\/p>\n<p>It should be noted that the first sighting of Escanor dates back to the first month of 2022. The malware is also distributed through a Telegram channel, where it has gained significant traction, approaching 30,000 subscribers.<\/p>\n<p>Additionally, Resecurity found that the domain name used by Escanor had previously been identified in connection with Arid Viper, a group active in the Middle East region in 2015 and known to primarily target Israeli assets.<\/p>\n<p>As for Escanor, most of its victims were identified in the US, Canada, the United Arab Emirates, Saudi Arabia, Kuwait, Bahrain, Egypt, Israel, Mexico, and Singapore, with some infections detected in Southeast Asia.<\/p>\n<p>The Escanor malicious payload is distributed using elaborate PDF and Office files, and it is worth noting that this malware also has a mobile version that works by intercepting one-time passwords sent to users of banking apps known as Esca RAT.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new remote administration tool called Escanor RAT arrives to deliver malicious code via Office and PDF files&#8230;..<\/p>\n","protected":false},"author":1,"featured_media":4264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"A new remote administration tool called Escanor RAT arrives to deliver malicious code via Office and PDF files.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-09T16:06:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1422\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code\",\"datePublished\":\"2022-09-09T16:06:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/\"},\"wordCount\":193,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/Escanor.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/\",\"name\":\"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/Escanor.jpg\",\"datePublished\":\"2022-09-09T16:06:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/Escanor.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/Escanor.jpg\",\"width\":2400,\"height\":1422,\"caption\":\"Virus detected alert. Camera moves around hud display and man typing keyboard. Cyber security breach warning with worm symbol on screen. System protection futuristic concept.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/","og_locale":"es_MX","og_type":"article","og_title":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog","og_description":"A new remote administration tool called Escanor RAT arrives to deliver malicious code via Office and PDF files.....","og_url":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-09-09T16:06:31+00:00","og_image":[{"width":2400,"height":1422,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code","datePublished":"2022-09-09T16:06:31+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/"},"wordCount":193,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/","url":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/","name":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg","datePublished":"2022-09-09T16:06:31+00:00","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/09\/Escanor.jpg","width":2400,"height":1422,"caption":"Virus detected alert. Camera moves around hud display and man typing keyboard. Cyber security breach warning with worm symbol on screen. System protection futuristic concept."},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/escanor-rat-uses-microsoft-office-and-adobe-pdf-documents-to-deliver-malicious-code\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Escanor RAT uses Microsoft Office and Adobe PDF documents to deliver malicious code"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4263"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4263\/revisions"}],"predecessor-version":[{"id":4265,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4263\/revisions\/4265"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4264"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}