HomeSecurityMicrosoft: Massive malware campaign distributes fake ransomware!

Microsoft: Massive malware campaign distributes fake ransomware!

A massive malware campaign has distributed the Java-based STRRAT RAT, known for its ability to steal data and disguise itself as ransomware. In fact, it is a fake ransomware. In tweets shared by Microsoft's security intelligence team, it described how this massive email campaign distributed fake ransomware payloadsusing compromised email accounts.

The spam emails urged recipients to open what looked like PDF attachments, but were actually images that downloaded RAT malware when someone clicked on them.

Also read: Craig Federighi: Macs are more vulnerable to malware than iPhones

Microsoft - Massive malware campaign - fake ransomware
Microsoft: Massive malware campaign distributes fake ransomware!

Microsoft said in its statement: “The emails contained an image that appeared as a PDF attachment, but when opened, linked to a malicious domain to download the malware “STRRAT”. This RAT is notorious for “behaving” like ransomware, appending the .crimson filename extension to files, but without actually encrypting them.”

Massive malware campaign - fake ransomware
Microsoft: Massive malware campaign distributes fake ransomware!

As the Microsoft team mentioned in its tweets, the “STRRAT” malware is designed to perform a fake ransomware attackwhile stealing its victims’ data in the background.

Karsten Hahn, a malware analyst at G DATA, said in June 2020 that the malware infects Windows devices via malicious email campaigns, promoting malicious JAR (Java ARchive) packages that distribute RAT payloads after two-stage VBScript scripts.

STRRAT records keystrokes, allows its operators to remotely execute commands, and steals sensitive data, including credentials from email clients and browsers, including Firefox, Internet Explorer, Chrome, Foxmail, Outlook, and Thunderbird.

See also: Teabot: New Android malware targets banks in Europe!

It also provides attackers with remote access to the infected machine by installing the open-source RDP Wrapper (RDPWrap) library , which enables Remote Desktop Host support on compromised Windows systems.

fake ransomware
Microsoft: Massive malware campaign distributes fake ransomware!

However, what makes it stand out from other RATs is the ransomware module that does not encrypt any of the victims' files, but only adds the “.crimson” to the files.

Although this does not prevent access to the file contents, some victims may still be fooled and, potentially, agree to pay a ransom to the attackers.

Proposal: Six ransomware gangs have "hit" 292 organizations in 2021!

Massive malware campaign
Microsoft: Massive malware campaign distributes fake ransomware!

Hahn pointed out: "This can work for blackmail, because such files can no longer be opened by double-clicking. Windows associates the correct program for opening files via their extension. If the extension is removed, the files can be opened as usual."

As Microsoft found during its analysis of last week's massive STRRAT campaign, malware developers have continued to improve it, expanding its modular architecture. However, the RAT's core functionality has remained largely the same, as it is still used to steal credentials from emails and browsers, execute remote commands or PowerShell scripts , and record victims' keystrokes

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS