HomeSecurityMalware analysis reveals sophisticated RAT

Malware analysis reveals sophisticated RAT

A new sophisticated remote access tool (Remote Access Trojan – RAT), which had been operating for weeks on a compromised system, has been detected and analyzed by security researchers.

See also: Interlock ransomware: Gang uses new NodeSnake RAT

advanced RAT

According to FortiGuard , the malware ran inside a legitimate Windows process and used advanced techniques , making it extremely difficult to recover and inspect. Specifically, it was found running inside the dllhost.exe with PID 8200.

The Portable Executable (PE) and DOS headers , which are critical for identifying and reconstructing malware files, were intentionally altered to thwart traditional analysis methods. Fortinet was only able to continue analysis using a full 33GB memory dump from the infected system .

For the purposes of the investigation, the team recreated the compromised environment and loaded the malware into a dllhost.exe with debugging enabled.

Locating the entry point required manual work, as traditional header information was not available. Ultimately, the entry point was found at memory address 0x1C3EEFEE0A8.

See also: Bitdefender antivirus: Fake site distributes Venom RAT

Because the malware relied on over 250 Windows API functions spread across 16 different libraries, each of them had to be manually re-deployed and patched for local execution. Required libraries that were not automatically loaded were manually imported using the LoadLibraryA() or LoadLibraryW().

Malware analysis reveals sophisticated RAT
Malware analysis reveals sophisticated RAT

Once activated, the malware decrypted the command and control (C2) server information, specifically the rushpapers.com and port 443, directly from memory.

Using the SealMessage() and DecryptMessage(), it encrypted and decrypted data packets before and after each transmission over TLS. The decrypted information revealed system information such as:
“OS: Windows 10 / 64-bit (10.0.19045)”.

The encrypted communication was based on a custom XOR algorithm. A randomly generated key was used for each transmission, adding an extra layer of concealment and detection avoidance.

Through dynamic analysis in a controlled environment, Fortinet confirmed the full functionality of this RAT, despite its stealthy installation and the obfuscation techniques it used.

See also: 'ResolverRAT' targets healthcare services

This highlights the need for multi-layered defense and modern malware detection techniques, such as behavioral analysis and memory monitoring, as traditional methods (e.g. signature-based) prove inadequate against such threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: infosecurity-magazine

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS