The Chinese hacking group «Webworm» is experimenting with adapting old malicious software for new attacks, which is likely to evade detection and reduce operational costs.
See also: US charges three Iranians for cyberattacks on CNI

The Webworm group is a cyberespionage cluster that has been active since at least 2017 and has been previously linked to attacks on IT companies, aerospace companies, and electricity providers in Russia, Georgia , and Mongolia.
According to a report by Symantec, threat actors are currently testing various modified Remote Access Trojans (RATs) against IT service providers in Asia, likely to determine their effectiveness.
See also: Seesaw messaging app: Parents of students received a message with an inappropriate photo
Old malware in new missions
The RATs used today by the Webworm team have been forgotten for many years. However, security tools still do not detect them easily.
The use of older RATs that are widely circulated and developed by various random hackers helps Webworm conceal its functions and combine them with the activities of others, making the work of security analysts much more difficult.
The first old malware used in new Webworm operations is the Trochilus RAT, which first appeared in 2015 and is now available for free via GitHub.
A modification added to Trochilus is that it can now load its configuration from a file by checking a set of hardcoded directories.
The second strain tested is the 9002 RAT, a popular malware among state-sponsored actors in the past decade, who valued it for its ability to inject itself into memory and execute stealthily.
The Webworm team added stronger encryption to the 9002 RAT's communication protocol to help avoid detection by modern traffic analysis tools .
The third malware family used in the attacks detected is the Gh0st RAT, first detected in 2008, which many APTs have used repeatedly in previous global cyber espionage operations.
The Gh0st RAT features multiple layers of obfuscation, UAC bypassing, shellcode unpacking, and memory, many of which are retained in the Webworm team's version.

A report by Positive Technologies from May 2022 named the modified malware “Deed RAT,” attributing it to a Chinese group they called “Space Pirates.” Symantec says it’s likely the same group as Webworm.
One of the new features of the Deed RAT, which is essentially a modified version of the Gh0st RAT, is a flexible C2 communication system that supports multiple protocols, including TCP, TLS, HTTP, HTTPS, UDP, and DNS.
Even though Space Pirates and Webworm are separate groups, Chinese hackers are known to “share” malware to hide their tracks and reduce development costs.
Information source: bleepingcomputer.com
