A new malware campaign has been discovered that relied on confidential financial data stolen from a bank to lure victims through phishing emails and deploy the malicious remote access trojan, known as BitRAT.
See also: ALPHV BlackCat: Clones victim's site for data leak

An unknown threat actor is believed to have taken control of the IT infrastructure of a Colombian cooperative bank, using the data to create convincing fake messages that would lure victims into opening dubious Excel documents.
Qualys, a leading cybersecurity company, was the first to disclose evidence of a widespread database breach consisting of more than 418 thousand records, which were gathered by exploiting SQL injection flaws.
See also: LockBit ransomware: Provides free decryptor to SickKids
The leaked information reveals the Cédula numbers (official national identity document), email addresses, phone numbers, customer names, payment records and salary details of Colombian citizens, as well as their residential addresses.
It appears that no previous disclosure of this information has been made on any darknet forums or online in general, meaning that threat actors were able to gain access to customer data without help and use it for their own malicious purposes.
The Excel file, containing the stolen banking documents, contains a macro designed to download and install BitRAT on the compromised system. This second-stage DLL payload extracts vital data from the machine at boot time.

According to Qualys researcher Akshat Pradhan, the BitRAT malware uses the WinHTTP library to download payloads from GitHub and store them in the %temp% directory.
In mid-November 2022, a repository was created on GitHub, which serves to store obfuscated BitRAT loader samples. These encrypted files are then decrypted and used to complete successful infection chains
See also: Google Home speakers are vulnerable to eavesdropping attacks!
BitRAT, an affordable and accessible malware available on the dark web for just $20, is packed with a variety of features. This malicious tool can be used to steal data, collect credentials, mine crypto , and download additional binaries.
Remote access trojans pose a huge risk to both individuals and businesses due to their ability to give hackers complete control over computers and networks. It is important for everyone to understand how these malicious programs work so they can better protect themselves.
Information source: thehackernews.com
