Trend Micro security researcher Maersk Menrige analyzed a Remote Access Trojan (RAT ) that uses Dropbox to operate its command and control (C&C) system.
According to Menrige, the upgraded PlugX RAT is the first trojan used in a targeted attack against the Taiwanese government, leveraging Dropbox to update the Command & Control (C&C) system settings, unlike other malware and ransomware that use the popular cloud storage platform to distribute malicious files.
The sophisticated Trojan also records victims' keystrokes and maps ports and installs remote shells, thus facilitating further data theft and exploiting vulnerabilities to carry out attacks.
"Using Dropbox helps to disguise malicious network traffic, as it is a legitimate website for storing files and documents," says Menrige.
Researcher Jake Williams has previously analyzed the use of Dropbox as an operational platform for handling and controlling malware in a related report he has published, but Menrige says this is the first time it has been exploited in malicious attacks.
For more information about the PlugX RAT attack and its actions, you can go to Trend Micro.
