Cybersecurity experts have recently identified a new dangerous Python-based malware capable of delivering devastating RAT capabilities, giving malicious actors complete remote control of affected systems.
See also: DEV-0569: Uses Google ads to compromise your network

PY#RATION, as security analysts at Securonix have named it, is a new RAT that uses the WebSocket protocol to communicate with the command and control (C2) server, while extracting data from victim computers.
A comprehensive technical report from the company analyzes how the malware works and reveals that developers are constantly innovating and upgrading it. In fact, since the PY#RATION campaign began in August, researchers have observed different versions of this remote access Trojan (RAT).
See also: Riot Games on recent hack: “We will not pay the ransom”
Distribution via shortcut files
The PY#RATION malware operates through a phishing campaign that uses password-protected ZIP file attachments containing two .LNK files disguised as images, specifically front.jpg.lnk and back.jpg.lnk, in order to infect computers with malware.

Upon launch, the victim of the shortcuts sees the front and back of the driver license. However, the malicious code is also executed to contact the C2 (Pastebin in later attacks) and download two .TXT files (“front.txt” and “back.txt”) which are eventually renamed to BAT files to serve as the malware execution path.
Upon activation, the malware deploys the 'Cortana' and 'Cortana/Setup' folders to the user's temporary directory, downloading multiple executable files from this location, which are decompressed and executed.
See also: Phishing scam: Australian sentenced to two years in prison
To establish persistence, a batch file (“CortanaAssist.bat”) must be added to the user's startup folder for continuous execution upon system startup
By using Cortana, Microsoft's personal assistant on Windows devices, malware entries can be disguised as legitimate system files.

PY#RATION RAT
The malware delivered to the target is a Python RAT, which is hidden and converted into executables by automated packagers such as 'pyinstaller' or 'py2exe'. This conversion process creates Windows executables that come with all the necessary libraries for execution.
This approach results in bloated payload sizes, with version 1.0 (initial) being 14MB and version 1.6.0 (latest) being 32MB. The latest version is larger because it has additional code (+1000 lines) and a fernet encryption layer.
This helps the malware evade detection, and according to Securonix's testing, version 1.6.0 of the payload was deployed undetected by all but one antivirus engine on VirusTotal.
Although Securonix failed to disclose the hash of its malicious samples, our research team at BleepingComputer did locate a file related to this campaign:

Using the 'pyinstxtractor' tool, Securonix analysts were able to analyze and evaluate the payload content as well as the functionality of the malware's code. This allowed them to determine its capabilities.

Version 1.6.0 of the PY#RATION RAT introduces a wide range of features.
Securonix researchers say the malware “leverages Python’s built-in Socket.IO framework, which provides functionality for both client and server WebSocket communication.” This channel is used for both communication and data extraction.
The advantage of WebSockets is that the malware can simultaneously receive and send data to and from the C2 over a single TCP connection using ports that are typically left open on networks such as 80 and 443.
Through their research, analysts observed that the same command and control address (“169[.]239.129.108”) was applied by hackers to all malware versions from 1.0 to 1.6.0 during this particular campaign.
The research team's findings confirmed that PY#RATION had been evading detection by IPVoid for months, as the scan showed that the IP address remained undetected.
Currently, details about the campaigns using this malware, its intended targets and distribution levels, as well as those responsible for it remain unknown.
Information source: bleepingcomputer.com
