HomeSecurityRAT malware campaign uses multilingual files to avoid detection

RAT malware campaign uses multilingual files to evade detection

RAT malware campaign uses multilingual files to evade detection: Operators of the StrRAT and Ratty remote access trojans (RAT) are running a new campaign using multilingual MSI/JAR and CAB/JAR files to evade detection by security tools.

RAT malware
RAT malware campaign uses multilingual files to evade detection

Deep Instinct discovered the campaign and identified two RATs used to attempt to evade detection by antivirus programs, despite both being known threats. This is an impressive feat given the age of these malware variants.

See also: Google Play Store and App Store are filled with fake ChatGPT apps

By leveraging the power of multilingual files, it is possible to combine two or more file formats in a seamless manner so that they can be launched and interpreted by multiple applications without any hassle.

For several years, cybercriminals have relied on multilingual files to hide their malicious code, mislead security solutions, and bypass security controls.

More recently, we observed the StrelaStealer malware exploiting this technique to target Outlook and Thunderbird accounts.

Despite Microsoft's attempt to address the difficulty by using a signature-based detection system, users are still able to bypass this security measure. As a result, multilingual files are exploited for malicious purposes.

RAT malware campaign uses multilingual files to evade detection
RAT malware campaign uses multilingual files to evade detection

Multilingual RAT campaign

Deep Instinct recently discovered a technique, which has been in use since 2018 and is used in the most recent RAT distribution campaign – combining JAR and MSI formats into a single.

It is easier for malicious actors to merge JAR and MSI files, since the former are distinguished by their final file, while the latter have a unique identifier at the beginning.

This dual format allows them to run as an MSI on Windows and also be executed as a JAR file by the Java runtime.

See also: Hackers exploit major vulnerability in Control Web Panel

Java Archive (JAR) files cannot be executed like executable files, which makes them harder for anti-virus tools. As a result, malicious code and the AV will only scan the MSI part of the file, which would otherwise appear clean. This increases the chances of a hacker penetrating your system unnoticed.

RAT malware campaign uses multilingual files to evade detection

Compared to other similar cases of the same two RAT families, Deep Instinct observed CAB/JAR combinations instead of MSI. Furthermore, due to their magic headers for interpreting file types, CABs are also ideal candidates when it comes to combining with JARs in a multilingual format.

This campaign uses polyglots delivered via Sendgrid and URL shortening solutions such as Cutt.ly and Rebrand.ly, while the StrRATs and Ratty payloads are kept secure on Discord servers.

Multilingual CAB/JARs were detected by six out of 59 AV engines on Virus Total, while 30 security vendors reported positive results for multilingual MSI/JARs. Thus, detection rates range from 10-50%.

RAT malware

According to Deep Instinct, many of the investigated StrRAT and Ratty malware programs communicate using a single C2 address and are hosted by an identical Bulgarian hosting provider.

See also: Royal Mail: Breach linked to LockBit ransomware group

Therefore, it is possible that both varieties are used in a single business run by the same person.

For those who don't know: A remote access trojan (RAT) is a malicious software program that allows an attacker to gain control of another computer and use it to steal data, monitor activity, or launch other attacks. RATs are typically spread through malicious websites or emails and can be used to spy on unsuspecting users and steal sensitive data.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS