HomeSecurityAtroposia malware kit increases cybercrime

Atroposia malware kit increases cybercrime

Cybercrime is becoming increasingly commercialized, significantly lowering the bar for hackers and making things harder for defenders. Varonis have discovered a plug-and-play toolkit, called Atroposia, that can be effectively used by even the least experienced threat actor for as little as $200 per month.

See also: New Phishing Kit automates the ClickFix attack process

Atroposia

Remote access trojan (RAT) uses nearly invisible tools and encrypted command channels to infiltrate systems, scan them for more exploitable vulnerabilities, steal credentials, monitor user activity, and take over machines at will.

How does Atroposia work?

Atroposia is promoted on underground forums as “a complete set of offensive capabilities.” These include stealthy remote desktop takeover, vulnerability scanning, full remote system shutdown, reboot and sleep capabilities, credential theft and privilege escalation, domain name service (DNS) hijacking, and error, report, and action logs (among other things). The control panel and plugin builder make it “surprisingly easy” to operate, according to Varonis researchers, and it’s low-cost: $200 per month, $500 for three months, or $900 for six months.

All command and control (C2) server communications are encrypted, and the malware can escalate privileges via User Account Control (UAC) bypass to gain administrator rights and install mechanisms that survive system reboots. The package’s hidden remote desktop, “HRDP Connect,” creates invisible sessions so users have no indication they have been compromised.

Hackers can open applications, view sensitive documents and emails, download or delete data, and manipulate workflows, acting as a “silent man on the desktop.” Atroposia’s built-in vulnerability scanner checks and detects missing software patches, insecure configurations, bugs, and outdated VPN clients. The results are provided as a score or report, essentially giving the attacker a picture of the system’s vulnerabilities.

See also: New 'Point-and-Click' Phishing Kit Bypasses Security Filters

Atroposia malware kit increases cybercrime

Atroposia is designed to run directly in memory and extract information in bulk. It does this with a grabber module that searches for files by extension or keyword (such as all PDF or CSV files), then compresses them into a password-protected ZIP file for extraction, Varonis researchers explain. This tactic leaves little trace. The package also allows threat actors to monitor victims’ clipboards in real time and record any cut-and-pasted information.

Additionally, attackers can perform “DNS hijacking” to redirect traffic, inject ads or malware, deploy fake software updates, and create openings for phishing and man-in-the-middle campaigns.

Atroposia is one of a growing number of RAT tools targeting businesses. Varonis has also recently discovered SpamGPT and MatrixPDF, a spam-as-a-service platform and a malicious PDF creator, respectively. Mirai, dating back to 2016, is probably the most successful example. However, Atroposia marks a “significant step” in the evolution of remote access tools, as it combines several advanced features into a single plug-and-play package. In particular, the integration of vulnerability scanning before the attacker even moves laterally is a “significant escalation.”

Because Atroposia uses encrypted command channels and often hides its user interface (UI), defenders should look for anomalies such as unexplained shadow Remote Desktop Protocol (RDP) sessions, unexpected DNS record changes, local vulnerability scans, and unusual clipboard activity. It is also recommended to validate the asset inventory, check for unknown remote desktop listeners or services, correlate anomalous user behavior (especially around privilege escalation or credential usage), and incorporate data access telemetry (such as file searches, compression, and extraction) into the alerting logic.

See also: MatrixPDF: New kit turns PDFs into phishing and malware baits

Atroposia malware kit increases cybercrime

Multi-factor authentication (MFA) is also critical, as is restricting administrator accounts and isolating endpoints.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS