HomeSecurityHorns&Hooves: New campaign distributes NetSupport RAT & BurnsRAT

Horns&Hooves: New campaign distributes NetSupport RAT & BurnsRAT

A new malicious campaign, dubbed Horns&Hooves, targets private users, retailers, and various service providers (mainly in Russia) to deliver the NetSupport RAT and BurnsRAT.

NetSupport RAT & BurnsRAT Horns&Hooves

The campaign has been dubbed Horns&Hooves by Kaspersky and has targeted more than 1,000 victims since March 2023. Victims are infected with the NetSupport RAT and BurnsRAT, which grant access to the target systems. Through this initial access, attackers can then install info-stealer malware, such as Rhadamanthys and Meduza.

The attacks begin with phishing emails that contain attachments that look like ZIP files. In reality, they contain JScript scripts. The script files are presented as requests and offers from potential customers or partners.

See also: ElizaRAT abuses Google, Telegram and Slack services

In some cases, the ZIP file contained documents related to the organization or person being impersonated (to increase the chances of the attack succeeding and opening the file with the malware).

One of the first samples identified as part of the Horns&Hooves campaign is an HTML Application (HTA) file that, when executed, downloads a PNG image (bait) from a remote server using the curl utility for Windows. At the same time, it secretly retrieves and executes another script (“bat_install.bat”) from a different server using the BITSadmin tool.

Using BITSadmin, the new script proceeds to download several other files, including the NetSupport RAT malware, which establishes contact with a command and control (C2) server.

A campaign observed in mid-May 2023 involved a JavaScript middleware that mimicked legitimate JavaScript libraries, such as Next.js, to trigger the NetSupport RAT infection chain.

Kaspersky said it also found another variant of the JavaScript file that installed an NSIS installer responsible for deploying BurnsRAT.

Although the backdoor supports commands for remote file download and execution, as well as various methods of executing commands via the Windows command line, the main mission of this component is to start the Remote Manipulator System (RMS) as a service and send the RMS session ID to the attackers’ server,” the researcher explained.

See also: LodaRAT malware: Targets Windows users and steals credentials

RMS is an application that allows users to interact with remote systems over a network. It provides the ability to manage the desktop, execute commands, transfer files , and exchange data between devices located in different geographical locations.“.

In a sign that threat actors continued to modify their modus operandi, two other attacks, detected in late May and June 2023, carried a completely revamped BAT file for installing the NetSupport RAT and embedded the malware directly into JavaScript code, respectively.

There are indications that the campaign is the work of a group known as TA569 (or Gold Prelude, Mustard Tempest, and Purple Vallhund).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Horns&Hooves: New campaign distributes NetSupport RAT & BurnsRAT
Horns&Hooves: New malicious campaign distributes NetSupport RAT & BurnsRAT

Protection against RAT malware

The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.

See also: Russian hackers exploit NTLM vulnerability to spread RAT Malware via Phishing emails

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known RAT malware.

You should also be careful with emails and messages you receive. Many RAT malware are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks (e.g. NetSupport RAT). Also, using two-factor authentication can add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS