
Java Remote Access Trojan (RAT) campaigns are no longer rare. Their traffic has increased in recent years and they continue to target businesses and individuals alike. The popularity of these campaigns is not surprising, as if an attacker infects a victim’s computer with a RAT, they can gain complete control of the computer. Along with this, these threats are not limited to just one operating system, but to any computer running Java. Attackers have easy access to Java RATs thanks to the fact that the source code is freely available on the internet.
As Symantec, they have noticed a new spam campaign distributing a Java RAT also known as JRAT, which started on February 13, 2014. The sender of the spam e-mail claims to have attached a payment certificate to the message and asks the user to confirm that they have received it.

The email actually contains a malicious attachment with the file name Paymentcert.jar, and is detected as Trojan.Maljava. If the Trojan is executed, it will run the JRAT, which is detected as Backdoor.Jeetrat. The RAT not only affects Windows PCs, but also computers running Linux, Mac OSX, FreeBSD, OpenBSD, and Solaris. This RAT is not new, as we have seen it in previous targeted attacks. The JRAT builder, as shown in the image below, shows how easy it is for an attacker to create their own custom RAT.
Symantec telemetry shows that the campaign has primarily affected the United Arab Emirates and the United Kingdom.
This campaign appears to be targeted at specific individuals. Certain aspects of the attack seem to confirm the targeted nature of the campaign, such as the small number of victims, a single sender of messages, a single server as a command and control (C&C) center, and the fact that the majority of these spam messages were sent to personal email addresses.
Symantec recommends that users exercise extreme caution when receiving unsolicited, unexpected, or suspicious emails. If you are unsure of the legitimacy of the email, then do not open it or, if you do open it, do not do what it asks you to do, such as click on links or open attachments.



