HomeSecurityTA505 group carries out new targeted attacks

TA505 group carries out new targeted attacks

TA505 group carries out new targeted attacks

People working at financial institutions in the US, the United Arab Emirates and Singapore appear to have become the new target of a Russian hacking, which is trying to infect them with a new malware that downloads a Trojan (RAT).

This is the TA505, which, as researchers at Proofpoint, has sent tens of thousands of emails containing the “AndroMut” downloader to users in the three countries. The group has also targeted users in South Korea in a separate but similar malicious campaign.

In both attacks, TA505 uses AndroMut to download “FlawedAmmyy,” a full-fledged RAT that allows attackers to gain administrator privileges on an infected device, thus being able to monitor user activity and steal credentials and other data.

FlawedAmmyy is a malware that first appeared in 2016 and is based on the source code of a legitimate remote administration tool called Ammyy.

Chris Dawson, head of threat intelligence at Proofpoint, said it's common for malicious actors to misuse remote management tools like Team Viewer and VNC to launch attacks. However, it's less common for a legitimate tool to be turned into standalone malware, as in the case of FlawedAmmyy.

The AndroMut downloader is new and was launched last month. The malware is written in C++ and appears to have some similarities to another downloader called Andromeda.

TA505 group carries out new targeted attacks

According to Dawson, the TA505 group, which was previously active in the field of global ransomware and banking Trojans, has changed its scope in recent years and is carrying out targeted attacks.

Its recent assets include many RATs and malware downloaders. Unfortunately, these attacks are silent and users do not initially realize that their system has been infected. They usually realize it when hackers steal their credentials or when they launch a new attack within the organization.

In addition to securing their emails and devices, organizations must also monitor their Command-and-Control systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS