In recent years, a mysterious hacking group has been creating trojanized hacking tools, which aim to infect fellow hackers in order to gain access to computers their.
According to a report by Cybereason , the trojanized tools were infected with a version of the njRAT malware , which allowed the hacking group to gain access to other hackers' systems
“To me, it looks like some person or group of people has found a clever way to gain access to more machines,” said Amit Serper, an executive at Cybereason.
“Instead of directly hacking the machines, they choose to infect the tools, distribute them for free and hack the people who use them,” Serper said, referring to a well-known tactic where hackers steal data that rival hackers have compromised.
Thousands of trojanized hacking tools have been circulating for years
Serper said that the Cybereason Nocturnus research team has identified over 1,000 samples of njRAT, but believes there are many more that have not yet been discovered.
Trojanized tools have been around for many years, but Serper says that this mysterious hacking group creates and releases new versions of the tools almost daily.
According to Cybereason, the backdoored tools are freely distributed on hacking forums and blogs. Some of the trojanized apps are regular hacking tools, while others are cracked programs, which allow wannabe hackers to use hacking tools without paying for a license.
The trojanized tools found by Cybereason include site scrapers, exploit scanners, Google dork generators, tools for performing automated SQL infections, tools for brute-force attacks , and tools for verifying the validity of leaked credentials

Additionally, Cybereason found trojanized versions of the Chrome browser .
According to Serper, many of the trojanized apps were linked to two domains. One of them, capeturk.com, was registered with the credentials of a Vietnamese citizen.
Often, domain owner information is misleading, especially when the domain is used in malicious campaigns. However, Serper said that many of the trojanized hacking tools uploaded to VirusTotaloriginated from a Vietnamese IP address.
According to Serper, the hacking group appears to be testing the detection rate of its malware on VirusTotal before releasing it on hacking forums, blogs, etc.
The use of the Vietnamese IP in uploads to VirusTotal, combined with the domain details, is a strong indicator that the gang does indeed originate from Vietnam.
Old tactic
As we mentioned above, the tactic of infecting hacking tools and giving them away for free is a well-known tactic. Many hackers have used it in the past.
This tactic is a fairly simple way to gain access to compromised data, without using other sophisticated hacking methods. Hackers who spread trojanized tools let other hackers download the tools, wait a few weeks to collect enough data, and then steal it using a backdoor, in this case the njRAT trojan.
