HomeSecurityFake job interviews distribute new Python RAT

Fake job interviews distribute new Python RAT

A new campaign being tracked as “Dev Popper” is targeting developers with fake job interviews in an attempt to trick them into installing a Python RAT.

See also: Russia: Konni RAT spread by government software

Python RAT

It asks developers to perform tasks supposedly related to the interview, such as downloading and running code from GitHub, in an attempt to make the whole process seem legitimate. However, the hackers' goal is to get them to download malware that collects system information and allows remote access to the host computer.

According to analysts at Securonix, the campaign distributing the Python RAT is likely orchestrated by North Korean hackers, based on the tactics they employ. However, the connections are not strong enough to be completely certain.

Multi-stage infection chain

"Dev Popper" attacks involve a multi-stage infection chain, based on social engineering, designed to deceive targets through a process of progressive compromise.

See also: Remcos RAT distributed through adult games

The attackers begin the Python RAT distribution process by posing as employers looking to fill software developer positions. During the interview, candidates are asked to download and execute what is presented as a typical coding assignment from a GitHub. The file is a ZIP containing an NPM package, which has a README.md as well as frontend and backend.

Fake job interviews

Once the developer runs the NPM package, a JavaScript (“imageDetails.js”) hidden within the support directory is activated, executing “curl” commands through the Node.js to download an additional file (“p.zi”) from an external server. Inside the file is the next-stage payload, a Python script (“npl”) that acts as a RAT.

Once the Python RAT is active on the victim's system, it collects and sends basic information to the command and control (C2) server, including the operating system type, hostname, and network data.

See also: Remcos RAT spreads via new version of IDAT loader

How do Remote Access Trojans work?

Remote Access Trojans (RATs), such as the Python RAT, are malicious software that allows attackers to gain access to and control a victim's computer remotely. This is achieved by installing the RAT on the target, usually through the use of techniques such as phishing or exploiting system vulnerabilities. Once installed, the RAT can perform a number of functions without the user's knowledge. These can include stealing personal data, installing other malware, changing system settings, or even disabling security systems. RATs are also known for their ability to create 'backdoors' in the victim's system, giving attackers permanent access even if the original malware is removed.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS