A new malware variant with a low detection rate, capable of delivering multiple Trojans to infected systems, has been discovered by researchers.
This week, the Cybersecurity team at Fortinet said that a recent sample reveals that the new malwrare is designed to deploy both RevengeRAT and WSHRAT to vulnerable Windows systems.
This particular sample initiates the infection process with JavaScript code and URL-encoded information contained in a text editor. Once decoded, the team found the VBScript full of character substitutions.
This VBScript code is then able to call a Shell.Application object that creates a new script file, A6p.vbs, which gathers a payload- an additional VBScript – from an external source.
The new code strings, which are also obfuscated in a possible attempt to evade detection, “pull” a script file called Microsoft.vbs from a remote server and store it in the Windows temporary folder .

Once the aforementioned code is executed, it creates a new WScript.Shell object and gathers OS environment and data with encoding, which will ultimately end up in the execution of the newly created script (GXxdZDvzyH.vbs) calling the VBScript interpreter with the” // B “parameter”, researchers say. “This activates the “batch-mode” and disables any warnings or alerts that may arise during execution.”
Subsequently, a new key is added to the Windows registry, PowerShell commands are executed to bypass execution policies, and the Revenge RAT payload is deployed.
Revenge RAT is a Trojan that has previously been linked to campaigns targeting financial institutions, governments , and IT companies.
After being installed by the new malware dropper, Revenge RAT connects to two command-and-control (C2) servers and collects system data from the victim before forwarding this information to the C2s.
IP addresses, volume data, machine names, user names, CPU data, language, and information regarding antivirus protection products and firewall installations have been stolen.
The Trojan is also capable of receiving commands from a C2 to load malicious ASM code into memory for additional exploits.
However, the deployment of a Trojan is not the end of the attack. The “malware dropper” also executes WSH RAT as a payload, using the same Microsoft.vbs script – with a few modifications.
The WSH RAT is often actively distributed in electronic “phishing” messages that are sent as known banks. The Trojan is publicly sold online on a subscription basis to threat actors.
Version 1.6 of the WSH RAT has been uploaded, and this malware contains more functionality than its counterpart, including persistence, data theft , and information processing methods
Among the 29 functions is the ability to check the permissions of the current user and “depending on which are used, it will remain as is or be «elevated» (startupElevate ()) to a higher level of user access”, say the researchers.
The Trojan will also perform a security check to disable the current security environment.
WSH RAT focuses on stealing information collected from popular browsers, such as Google Chrome and Mozilla Firefox. However, the malware also contains other features, such as executing files, rebooting the victim's machine, uninstalling programs , and keylogging.
It is also worth noting that in the malware space this month we saw Emotet with new features. The modular malware, which has proven popular with cybercriminals, now appears to be using new tactics.
