WildPressure is a new APT (Advanced Persistent Threat) hacking group that targets organizations located in the Middle East by delivering the Milum RAT to them in order to gain remote access and therefore control of the targeted device. The Milum RAT was first detected in a campaign conducted by Kaspersky in August 2019, while the RAT was written in the C++. It is worth noting, however, that the new malware campaign does not appear to have any similarities to any previous campaigns.

WildPressure malware campaign targets Middle East region
The APT hacker group has been targeting industrial sectors in the Middle East since May 2019, when the Milum RAT’s propagation mechanism was not yet known. The Trojan, called Milum, installs itself on the targeted device as an invisible toolbar window, which has as its main function the creation of a separate thread for communication.
Kaspersky researchers also found that the malware performs several zlip compression operations, such as zlibVersion, inflate or deflate.
Then, by decoding the configuration data of the targeted device, Milum obtains parameters such as “clientid” and “encrypt_key” to use in encryption .
The C2 communication protocol is over HTTP and has the version malware-1.0.1. This proves that it is in the early stages of development.
The RC4 algorithm is the only algorithm used with different 64-byte keys based on the victim. Based on the C2 domains (upiserversys1212[.]Com), the majority of visitor IPs come from the Middle East.

To launch the campaign, the APT hackers rented virtual private servers (VPS) from OVH and registered domains with an anonymizing proxy service. WildPressure appears to be a new group whose operation is unique, as it bears no resemblance to other malware campaigns.
