A hacker using the name Pahan carried out an amazing series by infecting his hacker colleagues with all kinds of malware, apparently for his own benefit.
The Internet is full of “hacking forums” where people can learn about hacking. They can even download or purchase hacking tools.
These are not places where you can find malware and exploits that are used by APTs (cyber-espionage) groups and that are difficult to detect even by the most up-to-date antivirus engines.
These are the places where common cyber-criminals plaster their final effort to develop malicious software, which, in most cases, is under close monitoring by security firms, mainly because these forums are also available through Google and are visible to everyone.
According to a report by Sophos, last year, a fraudster spent most of his time targeting other hackers alongside regular users.
Using the names Pahan, Pahan12, Pahan123 or Pahann, this user was posting advertisements for various hacking tools on various hacking forums, but Sophos had discovered that all of these tools were infected with malware.
The most likely motives for his actions are that he was trying to learn what the other hackers were «scanning»» or he was trying to develop keyloggers to steal passwords and take control of the malware / botnet control panels.
Sophos reported three cases when Pahan tried to infect others with malware-infected malwares.
The first case stems from an advertisement on an underground hacking forum, where Pahan provided a free download of Aegis Crypter, a tool for obfuscating and hiding malware from antivirus scanners. According to Sophos, the tool was infected with the RxBot trojan.
The second incident dates back to March 2016, when Pahan (using the alias Pahann) was selling a version of the KeyBase keylogger that infected its buyers with the COM Surrogate malware, which then in turn downloaded RxBot, a Trojan that captures computers within a botnet.
The latest incident dates back to July 2016, on LeakForums, where Pahan, using the name Pahan12, offered a free version of a PHP-based RAT (Remote Access Trojan) called SLICK RAT. Sophos researcher Gabor Szapannos says that SLICK RAT infected its victims with the KeyBase keylogger, which collects passwords and sends the data back to Pahan.
It is unknown how many would-be hackers were infected with Pahan's malware, but as we saw with the recent release of a RAT named Revenge, these days, hackers expect the hacking tools they download from such forums to have some kind of backdoor and usually perform a code check before installing anything on their computers.




