HomeSecurityFake Trump sex scandal video spreads QNode RAT

Fake Trump sex scandal video distributed by QNode RAT

Security researchers at Trustwave have discovered a malspam campaign distributing the trojan (RAT), using a fake Trump sex scandal video as bait.

As Security Affairs reports, the spam emails use the subject line “GOOD LOAN OFFER!!”and have a Java Archive (JAR) file attached called “TRUMP_SEX_SCANDAL_VIDEO.jar.” When the attachment is executed, the malicious code attempts to install the Qnode RAT on the recipient’s machine.

spam campaign

The researchers said in a statement: "While checking spam traps, one particular campaign caught our attention, mainly because the name of the attached file in the email does not match the subject line in the body of the email. We suspect that malicious actors are trying to continue the frenzy caused by the recent presidential election, with the file name they used in the attachment having no relation to the subject line of the email."

The downloader distributed in this malspam campaign, which uses a fake Trump sex scandal video as a “bait,” appears to be a variant of the QRAT downloader discovered by Trustwave researchers last August. In addition, the researchers highlighted some similarities to older variants, such as hiding the JAR file with Allatori Obfuscator, supporting only Windows , and the fact that the Node.Js installer was retrieved from the official nodejs.org site.

The QRAT variant continues to have multi-stage downloaders. The first downloader is the JAR file used as an attachment in the spam email. As detailed in the August report published by Trustwave, the first user has two major tasks – first it installs the Node.Js platform on the system, and then it downloads and executes the second stage downloader. The second stage downloader, called “wizard.js,” executes the Qnode RAT from a command-and-control (C2) server, attempting to achieve persistence on the infected system.

Fake Trump sex scandal video distributed by QNode RAT

The new variant used in the campaign in question has the following characteristics:

  • The JAR sample is significantly larger than that used in previous campaigns
  • The hackers behind this campaign added a GUI and a supposed Microsoft ISC license to the JAR code.
  • This variant does not use the string “qnodejs” to avoid detection and the downloader code was split into different buffers within the JAR
  • When downloading the next-stage malware, only the “–hub-domain” when communicating with the command-and-control servers
  • The JAR file downloads a file named “boot.js” and saves it to %temp%\_qhub_node_{random}

Additionally, QRAT supports many RAT features, such as retrieving system information, performing file operations, and obtaining credentials . Finally, this variant supports many applications, including Chrome, Firefox, Thunderbird, and Outlook.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS