A new sophisticated remote access tool (Remote Access Trojan – RAT), which had been operating for weeks on a compromised system, has been detected and analyzed by security researchers.
See also: Interlock ransomware: Gang uses new NodeSnake RAT

According to FortiGuard , the malware ran inside a legitimate Windows process and used advanced techniques , making it extremely difficult to recover and inspect. Specifically, it was found running inside the dllhost.exe with PID 8200.
The Portable Executable (PE) and DOS headers , which are critical for identifying and reconstructing malware files, were intentionally altered to thwart traditional analysis methods. Fortinet was only able to continue analysis using a full 33GB memory dump from the infected system .
For the purposes of the investigation, the team recreated the compromised environment and loaded the malware into a dllhost.exe with debugging enabled.
Locating the entry point required manual work, as traditional header information was not available. Ultimately, the entry point was found at memory address 0x1C3EEFEE0A8.
See also: Bitdefender antivirus: Fake site distributes Venom RAT
Because the malware relied on over 250 Windows API functions spread across 16 different libraries, each of them had to be manually re-deployed and patched for local execution. Required libraries that were not automatically loaded were manually imported using the LoadLibraryA() or LoadLibraryW().

Once activated, the malware decrypted the command and control (C2) server information, specifically the rushpapers.com and port 443, directly from memory.
Using the SealMessage() and DecryptMessage(), it encrypted and decrypted data packets before and after each transmission over TLS. The decrypted information revealed system information such as:
“OS: Windows 10 / 64-bit (10.0.19045)”.
The encrypted communication was based on a custom XOR algorithm. A randomly generated key was used for each transmission, adding an extra layer of concealment and detection avoidance.
Through dynamic analysis in a controlled environment, Fortinet confirmed the full functionality of this RAT, despite its stealthy installation and the obfuscation techniques it used.
See also: 'ResolverRAT' targets healthcare services
This highlights the need for multi-layered defense and modern malware detection techniques, such as behavioral analysis and memory monitoring, as traditional methods (e.g. signature-based) prove inadequate against such threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: infosecurity-magazine
