RAT malware campaign uses multilingual files to evade detection: Operators of the StrRAT and Ratty remote access trojans (RAT) are running a new campaign using multilingual MSI/JAR and CAB/JAR files to evade detection by security tools.

Deep Instinct discovered the campaign and identified two RATs used to attempt to evade detection by antivirus programs, despite both being known threats. This is an impressive feat given the age of these malware variants.
See also: Google Play Store and App Store are filled with fake ChatGPT apps
By leveraging the power of multilingual files, it is possible to combine two or more file formats in a seamless manner so that they can be launched and interpreted by multiple applications without any hassle.
For several years, cybercriminals have relied on multilingual files to hide their malicious code, mislead security solutions, and bypass security controls.
More recently, we observed the StrelaStealer malware exploiting this technique to target Outlook and Thunderbird accounts.
Despite Microsoft's attempt to address the difficulty by using a signature-based detection system, users are still able to bypass this security measure. As a result, multilingual files are exploited for malicious purposes.

Multilingual RAT campaign
Deep Instinct recently discovered a technique, which has been in use since 2018 and is used in the most recent RAT distribution campaign – combining JAR and MSI formats into a single.
It is easier for malicious actors to merge JAR and MSI files, since the former are distinguished by their final file, while the latter have a unique identifier at the beginning.
This dual format allows them to run as an MSI on Windows and also be executed as a JAR file by the Java runtime.
See also: Hackers exploit major vulnerability in Control Web Panel
Java Archive (JAR) files cannot be executed like executable files, which makes them harder for anti-virus tools. As a result, malicious code and the AV will only scan the MSI part of the file, which would otherwise appear clean. This increases the chances of a hacker penetrating your system unnoticed.

Compared to other similar cases of the same two RAT families, Deep Instinct observed CAB/JAR combinations instead of MSI. Furthermore, due to their magic headers for interpreting file types, CABs are also ideal candidates when it comes to combining with JARs in a multilingual format.
This campaign uses polyglots delivered via Sendgrid and URL shortening solutions such as Cutt.ly and Rebrand.ly, while the StrRATs and Ratty payloads are kept secure on Discord servers.
Multilingual CAB/JARs were detected by six out of 59 AV engines on Virus Total, while 30 security vendors reported positive results for multilingual MSI/JARs. Thus, detection rates range from 10-50%.

According to Deep Instinct, many of the investigated StrRAT and Ratty malware programs communicate using a single C2 address and are hosted by an identical Bulgarian hosting provider.
See also: Royal Mail: Breach linked to LockBit ransomware group
Therefore, it is possible that both varieties are used in a single business run by the same person.
For those who don't know: A remote access trojan (RAT) is a malicious software program that allows an attacker to gain control of another computer and use it to steal data, monitor activity, or launch other attacks. RATs are typically spread through malicious websites or emails and can be used to spy on unsuspecting users and steal sensitive data.
Information source: bleepingcomputer.com
