HomeSecurityHackers use BatCloak to make their malware fully...

Hackers use BatCloak to make their malware completely undetectable

A completely undetectable (FUD) malware obfuscation engine called BatCloak has been used to deploy various malware strains since September 2022, persistently evading detection from antiviruses.

See also: Fortinet: Fixes critical RCE flaw in Fortigate SSL VPN

BatCloak

The samples provide “threat actors with the ability to easily load numerous malware families and exploits via highly disguised batch files,” Trend Micro researchers said.

About 79.6% of the total 784 artifacts discovered are undetectable by all security solutions, the cybersecurity firm added, highlighting BatCloak's ability to bypass traditional detection mechanisms.

The BatCloak engine is the core component of a ready-made batch file creation tool called Jlaive, which has capabilities to bypass the Antimalware Scan Interface (AMSI), as well as compress and encrypt the primary payload to achieve increased security evasion.

See also: Strava: Loophole allows access to home addresses

The open-source tool, although deprecated since being made available via GitHub and GitLab in September 2022 by a developer named ch2sh, has been advertised as an “EXE to BAT crypter.” It has since been cloned and modified by other entities and ported to languages ​​like Rust.

Hackers use BatCloak to make their malware completely undetectable

The final payload is encapsulated using three layers of loaders: a C# loader, a PowerShell loader, and a batch loader—the latter of which acts as a starting point for decoding, unpacking each stage, and ultimately firing the hidden malware.

BatCloak has reportedly received numerous updates and tweaks since its release, with its most recent version being ScrubCrypt, which was first spotted by Fortinet FortiGuard Labs in connection with a cryptojacking conducted by the 8220 Gang.

"The decision to move from an open-source framework to a closed-source model, taken by the ScrubCrypt developer, can be attributed to the achievements of previous projects such as Jlaive, as well as the desire to monetize the project and secure it against unauthorized reproduction," the researchers said.

See also: Pink Drainer group impersonates journalists in phishing attacks

Additionally, ScrubCrypt is designed to be interoperable with several well-known malware families such as Amadey, AsyncRAT, DarkCrystal RAT, Pure Miner, Quasar RAT, RedLine Stealer, Remcos RAT, SmokeLoader, VenomRAT, and Warzone RAT.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS