A new variant of the Bandook Remote Access Trojan (RAT) is being distributed via phishing attacks , aiming to infiltrate Windows systems .

Fortinet FortiGuard Labs, which detected the malicious activity in October 2023, said the malware is distributed via a PDF file in phishing email a , which embeds a link to a password-protected .7z file
" After the victim extracts the malware with the password in the PDF file, the malware injects its payload into msinfo32.exe ," said security researcher Pei Han Liao.
See also: Krasue RAT: Hides in Linux servers using embedded rootkits
The Bandook trojan was first detected in 2007 and has many features that allow it to remotely gain control of infected systems.
In July 2021, cybersecurity ESET analyzed a cyberespionage campaign that used an upgraded variant of Bandook to compromise corporate networks in Spanish-speaking countries.
The starting point of the latest attack is an injector component designed to decrypt and load the payload into msinfo32.exe, a legitimate Windows binary that collects system information to diagnose computer.
The malware creates persistence on the compromised host, as well as communication with the command-and-control server to retrieve additional malicious payloads.
See also: Chinese hackers target Uzbekistan and South Korea with SugarGh0st RAT
According to Han Liao, these actions can be broadly categorized as file manipulation, registry manipulation, information retrieval and theft, file, control of the victim's computer, process termination, malware uninstallation, and more.

RAT malware
RATs, or Remote Access Trojans, have evolved significantly in recent years. Initially, they were simple tools used for remote system, but over time, they have evolved into complex and dangerous tools for carrying out malicious attacks.
Modern RATs are designed to systems security and remain hidden, allowing attackers to gain access to personal information, spy on users, and control their systems.
See also: NetSupport RAT: Attacks on government and educational organizations
Additionally, RATs have evolved to incorporate features such as encryption, the ability to download and execute additional malware, and the ability to automatically update themselves to stay one step ahead of detection and protection technologies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, RATs have evolved to become more aggressive , with the ability to attack large organizations and government systems, causing significant damage and information leaks
Source: thehackernews.com
