HomeSecurityChaChi: The new malware used in attacks against educational institutions

ChaChi: The new malware used in attacks against educational institutions

The PYSA ransomware gang is using a remote access Trojan (RAT) written in the Golang (Go) programming language in new attacks against healthcare and educational institutions in the United States. ChaChi designed to steal data, which is then used in double-digit extortion tactics to demand ransom from victims. The BlackBerry Threat Research and Intelligence reported on June 22 that the new ChaChi malware is also being used as a key component in ransomware attacks.

Read also: New malware prevents victims from visiting “pirate sites”

As we mentioned earlier, ChaChi is written in GoLang, a programming language now widely adopted by threat actors, in a shift from C and C++, due to its flexibility and ease of cross-platform code writing.

ChaChi - new malware
ChaChi: The new malware used in attacks against educational institutions

According to Intezer, there has been an increase of approximately 2,000% in Go-based malware samples in recent years.

ChaChi was discovered in the first half of 2020 , and the initial variant of the RAT Trojan was linked to cyberattacks against French authorities , as reported by CERT France in an Indicators of Compromise (IoC) report. However, now, a much more sophisticated variant of the malware has emerged

See also: How does the new Siloscape malware compromise “Kubernetes clusters”?

ChaChi new malware
ChaChi: The new malware used in attacks against educational institutions

The most recent available samples have been linked to attacks against major US educational institutions.

Compared to the first ChaChi variant, which had law-level capabilities, the malware is now capable of performing typical RAT activities, including backdoor creation and data exfiltration, as well as credential dumping via the Windows Local Security Authority Subsystem Service (LSASS), network enumeration, DNS tunneling, SOCKS proxy functionality, service creation, and lateral movement between networks.

The malware also uses a publicly available GoLang tool, gobfuscate, for obfuscation purposes. ChaChi takes its name from Chashell and Chisel, two tools used by the malware during attacks that have been modified for these purposes. Chashell is a reverse shell against the DNS provider, while Chisel is a port-forwarding system.

ChaChi - new malware
ChaChi: The new malware used in attacks against educational institutions

Proposal: Europe: Serious cyberattacks doubled in 2020

BlackBerry researchers believe the Trojan is the work of the PYSA/Mespinoza gang, a group that has been active in the threat landscape since 2018.This group is known for running ransomware campaigns and using the .PYSA when encrypting victims’ files. PYSA stands for “Protect Your System Amigo.

The FBI has previously issued warnings about an increase in attacks by this gang against schools in the UK and the US.

According to the researchers, the gang mainly focuses on high-profile targets who can pay huge ransoms. Finally, the attacks are usually controlled by a human operator and not by a task of automated tools.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS