HomeSecurityWhy do njRAT Trojan operators use Pastebin?

Why do njRAT Trojan operators use Pastebin?

Operators of the njRAT Remote Access Trojan (RAT) are leveraging Pastebin C2 tunnels to evade scrutiny by cybersecurity researchers.

Pastebin Trojan njRAT

On Wednesday, Palo Alto Networks' Unit 42 cybersecurity team said that njRAT, also known as Bladabindi, is used to download and execute secondary-stage payloads from Pastebin, completely eliminating the need to create a traditional command-and-control (C2) server.

Since at least October, attackers have used the Pastebin platform to host payloads that vary in format and shape.

The team says that njRAT variants will require shortened URLs that link to Pastebin in an attempt to "avoid detection by security products and increase the likelihood that the operation will go unnoticed."

njRAT is a widely used Trojan that is capable of remotely disrupting the functions of a compromised machine, including taking screenshots, exfiltrating data , and many other processes. In addition, the RAT is capable of executing secondary payloads and connecting infected computers to botnets.

The “Pastebin C2 tunnel” now in use, as described by the researchers, creates a path between njRAT infections and the new payloads. The Trojan, acting as a downloader, will “steal” encrypted data that has been dumped on Pastebin.

In some samples the team saw, a payload was decoded as a .NET executable that abuses Windows for keylogging and data theft. Other samples, similar in function, required multiple layers of decoding to reveal the final payload.

Palo Alto says that the Pastebin-based command architecture is still active and used by the RAT to deliver secondary payloads.

Source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS