[su_heading size=”18″]The perfect technique to avoid detection of RATs: Cybercriminals use fileless malware combined with steganography[/su_heading]
Security firm SentinelOne has discovered a new technique being exploited by malware developers, which involves hiding the most dangerous parts of Remote Access Trojans (RATs) inside the operating system's memory and using PNG files as configuration files.
Researchers first observed this practice in a series of state-sponsored attacks against Asian countries. The malware used to carry out the attacks was NanoCore (also known as Nancrat), a RAT first detected in the spring of 2014.
In this particular campaign, the threat was distributed as an EXE file, which when executed, in turn exported a second executable. The first executable, which did not exhibit malicious behavior, was stored on disk, while the second executable was directly injected into the system memory, with the help of an encrypted DLL and a series of PNG files.
According to SentinelOne researchers, and since the second HEX never “touches” the storage space, classic antivirus solutions cannot detect its malicious behavior, and only security products that scan the operating system's memory are able to detect it.
And if you're wondering what the role of PNG files is, it's to store the settings needed for RATs to function. All the images used are just a mess of random pixels, but when the second executable reads their contents, those pixels form parts of the RAT's payload as well as its configuration settings.

