HomeSecurityPhishing attacks distribute FatalRAT malware

Phishing attacks distribute FatalRAT malware

Several industrial organizations in the Asia-Pacific (APAC) region are being targeted by a new phishing attack distributing the FatalRAT malware.

FatalRAT malware phishing

“ The attack was orchestrated by attackers using the legitimate Chinese cloud content delivery network (CDN) myqcloud service Youdao Cloud Notes as part of their attack infrastructure and the ,” Kaspersky ICS CERT said

The researchers also explained that the attackers used a sophisticated, multi-stage payload delivery framework to ensure detection avoidance.

Phishing attacks primarily target government agencies and industrial organizations, particularly in the construction, information technology, telecommunications, healthcare, energy, logistics, and transportation. Target organizations are primarily located in Taiwan, Malaysia, China, Japan, Thailand, South Korea, Singapore, the Philippines, Vietnam, and Hong Kong.

See also: Hackers exploit ClickFix to deploy NetSupport RAT

The phishing emails distributing FatalRAT include attachments that indicate the campaign is designed for Chinese speakers.

Specifically, the phishing emails contain a ZIP file with a Chinese filename. When opened, it launches the first-stage loader which, in turn, makes a request to Youdao Cloud Notes to retrieve a DLL file and a FatalRAT configurator.

The configurator module downloads the contents of another note from note.youdao[.]com, so it can access the configuration information. It also opens a decoy file to attract the attention of targets there.

The DLL, on the other hand, is a second-stage loader that downloads and installs the FatalRAT payload from a server (“myqcloud[.]com”), while displaying a fake error message about a problem with the application execution.

The phishing campaign involves the use of DLL side-loading to promote multi-stage infection and load the FatalRAT malware.

According to Kaspersky, attackers exploit the functionality of legitimate binaries to make the chain of events look like normal activity.

See also: Fake Google Chrome sites distribute ValleyRAT malware

Researchers say that FatalRAT performs 17 checks to see if it is running in a virtual machine or sandbox environment. If any of the checks fail, the malware stops executing.

It also terminates all instances of the rundll32.exe process and collects information about the system and various security solutions installed. It then receives instructions from a command and control (C2) server to perform more malicious activities.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

FatalRAT is a trojan that records keystrokes, corrupts the Master Boot Record (MBR), turns the screen on/off, searches and deletes user data in browsers such as Google Chrome and Internet Explorer, downloads additional software such as AnyDesk and UltraViewer, performs file operations, starts/stops a proxy, and terminates arbitrary processes.

It is currently unknown who is behind the phishing attacks that distribute the FatalRAT malware.

Phishing attacks distribute FatalRAT malware

“The functionality of FatalRAT gives an attacker almost unlimited possibilities for developing an attack: spreading across a network, installing remote management tools, manipulating devices, stealing and deleting confidential information,” the researchers said.

Protection against RAT malware

The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.

See also: RAT Attacks: What They Are and How You Can Protect Yourself

You should also be careful with emails and messages you receive. Many RAT malware (FatalRAT malware) are spread through phishing attacks, so avoid opening attachments or clicking on links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS