HomeSecurityChinese hackers target Uzbekistan and South Korea with SugarGh0st...

Chinese hackers target Uzbekistan and South Korea with SugarGh0st RAT

A Chinese hacking group to be behind a malicious campaign targeting the Uzbek Foreign Ministry and users South Korean with a remote access trojan, called SugarGh0st RAT.

Chinese hackers target Uzbekistan and South Korea

The campaign began in August 2023 with two different infection sequences to deliver SugarGh0st, which is a customized variant of the Gh0st RAT (also known as Farfli).

According to Cisco Talos, the malware has features that “facilitate remote management tasks, as directed by the C2.”

See also: FjordPhantom: Android malware uses virtualization to evade detection

The attacks begin with a phishing email containing a malicious document. Opening the document initiates a multi-stage process that leads to the deployment of the SugarGh0st RAT.

The decoy document is embedded in a highly obfuscated JavaScript dropper contained in a Windows Shortcut file, which is embedded in the RAR archive email attachment.

“The JavaScript decodes and installs embedded files in the %TEMP% folder, including a batch script, a custom DLL loader, an encrypted SugarGh0st payload, and a fake document,” the researchers said.

The decoy document is then displayed to the victim, while, in the background, the batch script executes the DLL loader, which, in turn, loads it with a copied version of a legitimate Windows executable rundll32.exe to decrypt and launch SugarGh0st.

See also: Artificial Intelligence (AI): Extremely effective in malware analysis

A second variant of the attack also starts with a archive containing a malicious Windows Shortcut file. The difference is that the JavaScript leverages DynamicWrapperX to execute the shellcode that launches SugarGh0st.

SugarGh0st, written in C++, establishes contact with a hard-coded command-and-control (C2) domain, allowing it to transmit system metadata to the server, launch a reverse shell, and execute commands.

It can also terminate processes, take screenshots, perform file operations, and clear the machine's event logs

Researchers believe that this malicious campaign may be linked to Chinese hackers due to the Chinese origin of the original Gh0st RAT. Another piece of evidence is the use of Chinese names in the “last modified by” field in the metadata of the decoy files.

See also: GoTitan botnet, PrCtrl RAT and other malware exploit Apache bug

Additionally, Chinese hackers have a history of targeting Uzbekistan.

 SugarGh0st RAT
Chinese hackers target Uzbekistan and South Korea with SugarGh0st RAT

Protection against RAT malware

To protect against rat malware, you should take some basic security measures:

First, it is important to install a reliable and up-to-date antivirus software. This will help you detect and remove rat malware from your system.

Secondly, you should be careful with the emails and attachments you receive. Do not open unsolicited emails or attachments from unknown senders, as they may contain rat malware.

Third, update your operating system and software . Updates often contain security improvements that can protect your system from rat malware.

Finally, you should implement strong passwords and avoid using the same passwords for multiple accounts. This will make it more difficult for malicious users to gain access to your system and install rat malware.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS