HomeSecurityWogRAT malware: Targeting Windows and Linux and aNotepad abuse

WogRAT malware: Targeting Windows and Linux and aNotepad abuse

A new malware called “WogRAT” targets Windows and Linux, abusing the online note-taking platform “aNotepad.” The platform is used to store and retrieve malicious code.

WogRAT malware Windows Linux

According to researchers at the AhnLab Security Intelligence Center (ASEC), the WogRAT malware (so named by the same researchers) has been active since at least late 2022, targeting Japan, Singapore, China, Hong Kong, and other Asian countries.

The distribution methods are unknown, but the names of the executable samples resemble popular software (flashsetup_LL3gjJ7.exe, WindowsApp.exe, WindowsTool.exe, BrowserFixup.exe, ChromeFixup.exe, HttpDownload.exe, ToolKit.exe). This could indicate that the distribution is done via malvertizing or other similar techniques.

See also: Kimsuky hackers use ScreenConnect bugs to distribute ToddleShark malware

Abuse of the aNotepad service

As mentioned above, the free online platform aNotepad was abused to host a base64-encoded .NET binary of the Windows version of the malware, disguised as an Adobe tool.

Being a legitimate online service, aNotepad is not blacklisted and is not treated suspiciously by security. When the WogRAT malware is first executed on the target computer, it will not be flagged by security tools, as it does not have any malicious functionality.

However, it contains encrypted source code for a malware downloader, which is compiled and executed immediately.

This downloader retrieves an additional malicious .NET binary stored in aNotepad, resulting in the loading of a DLL, which is the WogRAT malware .

WogRAT malware aNotePad

The WogRAT malware sends some basic information about the infected system to the command and control (C2) server controlled by the attackers. It then receives further commands to execute.

See also: Stuxnet-like attack via online PLC malware

There are five supported functions:

  • Executing a command
  • Download a file from a specified URL
  • Upload file to C2
  • Waiting for a specified time (in seconds)
  • Vacation

WogRAT malware: Linux version

The Linux of WogRAT, which is available in ELF format, is quite similar to the version targeting Windows systems. However, it uses Tiny Shell for routing functions and additional encryption in communication with the C2.

TinySHell is an open source backdoor that facilitates data exchange and command execution on Linux systems.

Additionally, in the Linux version of the WogRAT malware, commands are not sent via POST requests, but are issued via a reverse shell created on a given IP and port.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ASEC analysts do not know how these ELF binaries are distributed to victims, as the Linux variant does not use aNotepad to host and retrieve malicious code.

See also: Pro-Hamas hackers target Israel with BiBi malware

More details can be found in the ASEC report

WogRAT malware: Targeting Windows and Linux and aNotepad abuse

One of the most effective methods of protecting against malware is to use reputable security. These software regularly scan your computer for malware detection and removal.

Keeping your operating system and applications up is also crucial. Updates often include security patches that can protect your computer from new malware threats (e.g. WogRAT).

Using strong passwords and changing them regularly can help protect against malware accessing your personal information.

Finally, careful interaction with the internet is essential. Avoid visiting suspicious websites, downloading files from untrusted sources, and clicking on links or attachments from unknown senders.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS