HomeSecurity“ResolverRAT” targets healthcare services

'ResolverRAT' targets healthcare services

Organizations in the healthcare and pharmaceutical industries have been targeted by a new, sophisticated malware family (ResolverRAT), according to an announcement from cybersecurity firm Morphisec.

See also: GitHub's new Sakura RAT evades AV & EDR protections

ResolverRAT

It is called ResolverRAT and has been observed in attacks up until March 10.This malware has advanced in-memory execution and multi-layered obfuscation capabilities, while relying heavily on runtime resolution mechanisms and dynamic resource management.

Despite similarities in attack methods, use of binaries, and payload transfer with previous phishing campaigns distributed by the Rhadamanthys and Lumma RATs, Morphisec researchers consider ResolverRAT to be a new malware family.

Based on fear, the phishing emails distributing the new malware trick company employees into clicking on a link, which leads them to download and open a file that executes ResolverRAT.

The attacker targets users in various countries, sending emails in their native languages ​​— such as Czech, Hindi, Indonesian, Italian, Portuguese, and Turkish — often referring to legal investigations or copyright violations

See also: SnowDog: New RAT malware advertised on hacking forums

The infection chain exploits the DLL search sequence violation technique, relying on a vulnerable executable file to load a malicious DLL located in the same folder.

'ResolverRAT' targets healthcare services

In the first stage of execution, a loader that uses multiple evasion techniques decrypts, loads, and executes the malicious payload. The ResolverRAT payload is compressed and protected with AES-256 encryption, with keys stored as disguised integers and only existing in memory after decryption.

To ensure its persistence, the malware creates up to 20 registry entries in multiple locations, masking registry key and file paths, while also installing itself in various parts of the system.

ResolverRAT also implements various mechanisms to protect the command and control (C&C) infrastructure, including a parallel trust system for certificate validation, which can bypass root authorities by creating a private chain of validation between the implant and the C&C.

RAT features a multithreaded architecture for command processing, incorporates robust error handling mechanisms to prevent crashes, supports persistent connectivity, and divides large data sets into chunks for transmission.

See also: Russian hackers Gamaredon target Ukraine with Remcos RAT

A Remote Access Trojan (RAT) is a type of malware that allows a remote user to control a computer without the owner's knowledge or consent. It is usually installed by tricking the user, such as by executing a suspicious file or visiting a malicious website. Once installed, a RAT can bypass security measures and give the attacker complete access to the system. This includes the ability to view the victim's screen, activate the camera or microphone, record keystrokes, transfer files, and even control other devices on the same network. Because of these capabilities, RATs are often used for espionage, data theft, or even sabotage. They are particularly dangerous because they operate silently in the background and are difficult to detect without the use of specialized security tools.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: securityweek

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS