The North Korean-linked group known as the Lazarus Group has been observed exploiting a now-patched critical vulnerability affecting Zoho ManageEngine ServiceDesk Plus to distribute a remote access trojan called QuiteRAT.

The targets include Internet backbone infrastructure and healthcare entities in Europe and the US, cybersecurity firm Cisco Talos said in a two-part analysis published today.
Additionally, a closer look at the adversary's recycled attack infrastructure used in cyberattacks on businesses has led to the discovery of a new threat called CollectionRAT.
The fact that the Lazarus Group continues to rely on the same technique despite the fact that these components have been documented for years highlights the trust hackers have in their businesses, Talos pointed out.
QuiteRAT is said to be a successor to MagicRAT, itself a continuation of TigerRAT, while CollectionRAT appears to have elements in common with EarlyRAT (also known as Jupiter), an implant written in PureBasic with capabilities for executing commands on the endpoint.
The use of the Qt framework is seen as a premeditated attempt by the adversary to make analysis difficult as it “increases the complexity of the malware.”
The activity, detected in early 2023, involved exploiting CVE-2022-47966, just five days after a proof-of-concept (Poc) for the flaw was made available online ,to directly deploy the QuiteRAT binary from a malicious URL.

Another critical difference between the two is the lack of a built-in persistence mechanism in QuiteRAT, which requires the command issued by the server to ensure continued operation on the compromised host.
The findings also overlap with another campaign uncovered by WithSecure last February, in which security vulnerabilities in unpatched Zimbra to compromise victim systems and ultimately install QuiteRAT.
Cisco Talos reported that the adversary is “increasingly downgrading to using open source tools and frameworks during the initial access phase of attacks , rather than rigorously implementing them in the post-breach phase.”
This includes the GoLang -based DeimosC2 framework , which is used to gain persistent access, with CollectionRAT primarily used to collect metadata , execute arbitrary commands , manipulate files on the infected system, and deliver additional payloads.
It is not immediately clear how CollectionRAT is spread, but evidence suggests that a modified copy of the PuTTY Link (Plink) program hosted on the same infrastructure is used to create a remote tunnel to the system and be used to serve the malware.
The development is a sign that the Lazarus Group is constantly changing tactics and expanding its malicious toolkit, while also exploiting newly disclosed software vulnerabilities with devastating consequences.
Information source: thehackernews.com
