HomeSecurityAdwind RAT back in the spotlight—with zero detection rate

Adwind RAT back in the spotlight—with zero detection rate

The Adwind remote access Trojan (RAT) has resurfaced after a few months with a series of targeted attacks. It's not your average RAT - it can completely bypass antivirus and claims a zero detection rate.

It was observed over the weekend in multiple targeted attacks against Danish companies, according to Heimdal Security. But since the malicious email used to scam victims is in English, the attackers likely don't stop at the Danish border.

Adwind RAT back in the spotlight—with zero detection rate

Adwind, which is essentially Java malware, is often associated with APT campaigns. Heimdal calls it “cross-platform, multifunctional, and simply destructive.”

Therefore, it has a dual purpose: To exfiltrate data from infected organizations and to open a backdoor, which allows attackers to inject more malware onto those infected machines. Successful Adwind infections give cybercriminals a backdoor into computers running Windows, OS X, Linux , and even Android. Once the RAT is on a system, attackers can remotely control the computer and collect key logs, capture camera and audio footage, take screenshots, and more.

In the attacks observed, once the Adwind code was executed, the infected computer was directly joined to the botnet.

Any machine running Java is potentially vulnerable, but the online criminals behind Adwind are part of a trend toward more targeted attacks that require a smaller infrastructure to proceed.

In terms of protection measures, administrators can build data security into layers and advise employees on how to detect malicious emails. Adwind is spread through malicious emails with the subject line “Quotation request”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS