HomeSecurityBandook RAT: New variant infects Windows systems

Bandook RAT: New variant infects Windows systems

A new variant of the Bandook Remote Access Trojan (RAT) is being distributed via phishing attacks , aiming to infiltrate Windows systems .

Bandook RAT Windows

Fortinet FortiGuard Labs, which detected the malicious activity in October 2023, said the malware is distributed via a PDF file in phishing email a , which embeds a link to a password-protected .7z file

" After the victim extracts the malware with the password in the PDF file, the malware injects its payload into msinfo32.exe ," said security researcher Pei Han Liao.

See also: Krasue RAT: Hides in Linux servers using embedded rootkits

The Bandook trojan was first detected in 2007 and has many features that allow it to remotely gain control of infected systems.

In July 2021, cybersecurity ESET analyzed a cyberespionage campaign that used an upgraded variant of Bandook to compromise corporate networks in Spanish-speaking countries.

The starting point of the latest attack is an injector component designed to decrypt and load the payload into msinfo32.exe, a legitimate Windows binary that collects system information to diagnose computer.

The malware creates persistence on the compromised host, as well as communication with the command-and-control server to retrieve additional malicious payloads.

See also: Chinese hackers target Uzbekistan and South Korea with SugarGh0st RAT

According to Han Liao, these actions can be broadly categorized as file manipulation, registry manipulation, information retrieval and theft, file, control of the victim's computer, process termination, malware uninstallation, and more.

Bandook RAT: New variant infects Windows systems
Bandook RAT: New variant infects Windows systems

RAT malware

RATs, or Remote Access Trojans, have evolved significantly in recent years. Initially, they were simple tools used for remote system, but over time, they have evolved into complex and dangerous tools for carrying out malicious attacks.

Modern RATs are designed to systems security and remain hidden, allowing attackers to gain access to personal information, spy on users, and control their systems.

See also: NetSupport RAT: Attacks on government and educational organizations

Additionally, RATs have evolved to incorporate features such as encryption, the ability to download and execute additional malware, and the ability to automatically update themselves to stay one step ahead of detection and protection technologies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, RATs have evolved to become more aggressive , with the ability to attack large organizations and government systems, causing significant damage and information leaks

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS