HomeSecurityHackers infected with their own RAT malware

Hackers infected with their own RAT malware

Hackers specializing in cyberespionage and seemingly linked to India were infected with their own custom RAT malware and accidentally exposed their activities to security researchers.

The hacking group has been active since at least December 2015 and is known as PatchWork, Dropping Elephant, Chinastrats, or Quilted Tiger.

See also: FBI: Hackers are mailing USB drives that install ransomware

RAT malware
Hackers specializing in cyberespionage were infected with their own RAT malware

During PatchWork's most recent cyberespionage campaign (from late November to early December 2021), Malwarebytes Labs observed hackers using malicious RTF documents impersonating Pakistani authorities to infect targets with a new variant of the BADNEWS RAT, known as Ragnatela.

Ragnatela RAT allows cybercriminals to execute commands, take screenshots, record keystrokes, collect sensitive files, deploy other payloads, and upload files.

“Ironically, all the information was collected thanks to the hacking group being infected with their own RAT, resulting in keystrokes and screenshots of their own computer and virtual machines,” explained the Malwarebytes Labs research team.

See also: AvosLocker ransomware: Linux version targets VMware ESXi servers

cyber espionage

After discovering that the PatchWork hackers were infecting their own development systems with the RAT, researchers were able to track them while they were using VirtualBox and VMware for testing and web development and testing on computers with dual keyboard layouts (i.e., English and Indian).

The researchers were also able to obtain information about the targets that the hacking group specialized in cyber espionage had breached. Some of the targets were the Ministry of Defense of Pakistan and several universities, such as the National Defense University of Islam Abad, the Faculty of Bio-Science of UVAS University, the Karachi HEJ Research institute, and SHU University.

“Thanks to the data captured by the hacking group’s own malware, we were able to better understand who was sitting behind the keyboard,” Malwarebytes Labs added.

See also: More and more DDoS attacks demanding ransom

“The group uses virtual machines and VPNs to deploy, push updates, and control its victims. Patchwork, like some other East Asian APT groups, is not as sophisticated as state-run hacking groups linked to Russia and North Korea.“.

hackers
Hackers infected with their own RAT malware

The hackers had targeted US think tanks in a spear-phishing campaign in March 2018, using the same tactic of pushing malicious RTF files to compromise victims' systems. They also used a variant of the QuasarRAT malware.

In January 2018, they were attempting to infect systems with the BADNEWS malware .

It was also behind a spear-phishing campaign targeting employees of a European government organization in late May 2016.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS