HomeSecurityGitHub's new Sakura RAT evades AV & EDR protections

GitHub's New Sakura RAT Evades AV & EDR Protections

A new remote access Trojan (RAT) named Sakura has been published on GitHub. Due to its advanced detection capabilities and extensive system control features, Sakura is causing serious concerns in the cybersecurity.

See also: GitHub supply chain attack detected on SpotBugs tokens

Sakura RAT

The malware, detected in a repository allegedly created by a user named “ Haerkasmisk ,” offers attackers an extensive toolkit that can bypass modern antivirus and Endpoint Detection and Response (EDR) solutions through multiple obfuscation techniques, similar to those seen in previous malware families.

The Sakura RAT has several advanced features that make it particularly dangerous. According to a Cyberfeeddigest shared on X, the RAT includes a stealth browser mode, allowing attackers to perform online activities through the victim's machine without being detected, as well as the Hidden Virtual Network Computing (HVNC) feature, which creates an invisible desktop for discreet remote control.

This malicious application reportedly uses techniques similar to those observed in previous RAT families, such as process injection, reflective DLL injection, and single-byte XOR encoding, in order to hide network communications and embedded chains, making the detection process significantly more difficult for security solutions.

Technically, Sakura appears to combine elements from various existing malware frameworks.

See also: GitHub: Updates Advanced Security for more security

Like the previously documented Sakula malware family identified by Dell SecureWorks, it likely uses HTTP GET and POST for command and control (C2) communications.

GitHub RAT
GitHub's New Sakura RAT Evades AV & EDR Protections

This toolkit reportedly maintains its persistence via Windows Run registry keys and can be configured as a service, similar to other advanced RATs.

The multi-session capability allows attackers to simultaneously control multiple compromised systems through a central control panel.

Security researchers have observed that the malware may exploit the CVE-2014-0322 or similar exploits as initial infection vectors, although the specific delivery mechanisms remain under investigation.

Sakura RAT joins a growing ecosystem of antivirus evasion tools that are publicly available. According to researchers investigating the “antivirus-evasion” topic on GitHub, several frameworks such as Veil, Chimera , and Process Herpaderping are openly accessible, contributing to the spread of malware that evades detection.

Experts say the availability of these tools dramatically lowers the barrier to entry for would-be attackers. What previously required significant expertise can now be accomplished using downloadable frameworks.

See also: Coinbase was the target of GitHub Actions breaches

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protecting against Remote Access Trojans (RATs) requires a combined approach that includes the use of security tools, proper system administration, and educational measures. Here are some steps to protect against these malicious viruses:

  1. Software Updates and Security Updates
  2. Network Security Upgrade
  3. Identifying and Preventing Uninvited Connections
  4. User Access and Rights Management
  5. User Assessment and Training
  6. Enabling and Using RAT Detection and Removal Tools
  7. Systems Monitoring and Analysis

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS