Skip to main content
Official Seqrite Distributor in Thailand
Threat researchOriginally published 19 June 2026 · Seqrite Labs

Attackers disguise RAR files as health-ministry documents to target Thai hospitals and clinics

Seqrite Labs found a malware campaign aimed squarely at Thai healthcare: RAR files named like CT-scan results or procurement approvals that end in stolen browser passwords.

Seqrite Labs has reported a malware campaign aimed directly at Thailand's healthcare sector. Targets range from Ministry of Public Health staff and hospital administration to radiology and dental clinics, clinical departments and medical-equipment procurement teams. The first sample surfaced on 7 April 2026 and the latest on 3 June 2026; every one was uploaded from Thailand.

Lures named after the victim's own work

Phishing emails carry RAR archives named to match the recipient's job — equipment approvals from the ministry, patient admission requests, X-ray queries, CT-scan results. Inside is not a document but an obfuscated batch file.

A "patient CT scan results" sample, first seen in Thailand (image: Seqrite Labs)
A "patient CT scan results" sample, first seen in Thailand (image: Seqrite Labs)

What happens when it's opened

  • The batch file uses PowerShell to decode the next stage, then deletes its temp files.
  • A loader pulls files posing as PNG images from GitHub and assembles the malware.
  • A script named WindowSecuryt.bat is dropped into the Startup folder so it runs at every logon.
  • It tries to escalate privileges on the machine.
  • A Python info-stealer closes Chromium browsers, lifts saved passwords, cookies and sessions, and sends them to the attacker's Telegram bots.

Seqrite assesses the activity as targeted but makes no firm attribution. Seqrite products detect it as Script.Trojan.Downloader.50836.GC; the full hash list and MITRE ATT&CK mapping are in the original write-up.

Not only big hospitals

Private clinics, labs and companies that supply hospitals are on the target list too. They rarely have a security team, and opening attachments from government bodies is a normal part of the job — which is exactly why attackers use it.

What a business should do

  • Treat .rar or .zip files that look like official or patient documents — and contain .bat files — as hostile.
  • Check the Windows Startup folder for new files you can't account for.
  • Restrict BAT and PowerShell scripts from user folders and %TEMP%.
  • Stop saving work passwords in the browser, and turn on MFA.

More news

Evaluate it in your own organisation

30 days, no cost, no commitment. We'll send a trial licence and install steps to the email you give us.

Or call 090-295-5556 · LINE @528gkanm