Cybersecurity researchers have analyzed a remote access trojan (RAT) known as Deuterbear, used by BlackTech hackers linked to China. The RAT is used for cyberespionage targeting the Asia-Pacific region.

Chinese BlackTech hackers have been active since at least 2007. The cyberattacks involved the development of a malware called Waterbear, which has been around for nearly 15 years. However, campaigns observed since October 2022 have also used an updated version called Deuterbear.
“ Deuterbear, while similar to Waterbear in many ways, exhibits improved features such as support for shellcode plugins, avoiding handshakes for RAT operation, and using HTTPS for C&C communication ,” said Trend Micro researchers Pierre Lee and Cyris Tseng.
“Comparing the two malware, Deuterbear uses a shellcode format, features anti-memory scanning, and shares a traffic key with its downloader, unlike Waterbear.“.
See also: SugarGh0st RAT malware targets AI companies
Waterbear is delivered via a legitimate executable file, which leverages DLL side-loading to launch a loader, which then decrypts and executes a downloader, which in turn contacts a command-and-control (C&C) server to retrieve the RAT.
The RAT is downloaded twice from the infrastructure controlled by the attackers. The first Waterbear RAT serves as a plugin downloader, while the second Waterbear RAT operates as a backdoor, collecting sensitive information from the compromised host ,via a set of 60 commands.
The infection route for Deuterbear is similar to that of Waterbear. Again, there are two stages for installing the RAT backdoor component.
The first stage uses the loader to launch a downloader program. This connects to the C&C server to retrieve the Deuterbear RAT. Persistence is created via a second stage loader, via DLL side-loading.
This loader is ultimately responsible for executing a downloader, which again downloads the Deuterbear RAT from a C&C server for information theft.
See also: Hackers FIN7: Malicious Ads to Distribute NetSupport RAT
“On most of the infected systems, only the second stage of Deuterbear is available,” the researchers said. “All elements of the first stage of Deuterbear are completely removed after the persistence installation is complete.”

“This strategy effectively protects their tracks and prevents the malware from being easily analyzed by threat researchers, especially in simulated environments rather than on real victim systems.“.
Trend Micro said that Waterbear has evolved, eventually leading to the emergence of a new malware, Deuterbear. “Interestingly, both Waterbear and Deuterbear continue to evolve independently, rather than replacing each other.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Protection
One of the most effective ways to protect users is through internet safety education. Users should be aware of the risks involved in downloading software from untrusted sources and clicking on ads that look suspicious.
Additionally, using a reputable antivirus software can provide significant protection. These programs can detect and remove suspicious programs before they can cause damage to the user's computer.
See also: Fake job interviews distribute new Python RAT
Finally, users should keep their operating system and all applications up to date. These updates often include security that can protect users from the latest threats.
Source: thehackernews.com
