Cybersecurity researchers have discovered that the BLOODALCHEMY malware, which is used in attacks against government organizations in South and Southeast Asia, is actually an upgraded version of the Deed RAT, which is considered a successor to ShadowPad.

"The origins of BLOODALCHEMY and Deed RAT lie in ShadowPad. Given ShadowPad's history of being used in multiple APT campaigns, it is critical to pay close attention to the increasing use of this malware," said Japanese firm ITOCHU Cyber & Intelligence.
Read also: JAVS software is used for supply chain attacks
BLOODALCHEMY was first documented by Elastic Security Labs in October 2023 in connection with a campaign organized by an intrusion tracked as REF5961 targeting countries in the Association of Southeast Asian Nations (ASEAN).
The backdoor , written in C, enters a process (called “BrDifxapi.exe”) via a technique known as DLL sideloading. This backdoor can replace the toolkit, collect information from the host, load additional payloads, and uninstall and then terminate.
"Although unconfirmed, the presence of so few effective commands suggests that the malware may be a minor component of a larger attack set or malware package that is still under development. Alternatively, it could be a focused piece of malware with a specific tactic," Elastic researchers noted.
See more: Ransomware attacks exploit VMware ESXi vulnerabilities
Attack chains have been observed to be deployed that compromise a maintenance account on VPN devices to gain initial access to the BrDifxapi.exe deployment. This file is then used to load BrLogAPI.dll, a loader responsible for executing the powershell code in memory, after extracting it from a file named DIFX.

The malware operates through a functional execution that defines its behavior. This allows it to evade analysis in sandbox environments, maintain its persistence, communicate with a remote server, and control the infected computer via backdoor commands.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
