HomeSecurityGlassRAT zero-detection Trojan targets Chinese nationals

GlassRAT zero-detection Trojan targets Chinese nationals

A previously undetectable remote management tool was discovered and its name is “GlassRAT.”

GlassRAT zero-detection Trojan targets Chinese nationals

The zero-detection Trojan appears to have been operating quietly for three years, according to RSA, and evidence suggests it is being used as part of a highly targeted campaign, targeting Chinese nationals in commercial organizations.

GlassRAT has many of the telltale signs of a good, highly effective piece of malware. Its dropper signs a tainted certificate from a trusted and well-known issuer. It then deletes itself once it has successfully delivered its payload. Once installed, the malicious DLL file remains under antivirus radar.

It is worth noting that the command and control structure of GlassRAT has been exposed as a brief overlay with CnC that was identified in the campaigns related to malware reported in 2012, which targeted governments and military organizations in the Pacific region.

Specifically, GlassRAT is linked to the Mirage malware CnC hosting, which in turn is linked to the Magicfire, PlugX, and Mirage malware that targeted the Philippine military and the Mongolian government.

Additionally, the time span of the C2 overlay was relatively short, a fact that suggests it may have happened by accident, as heard in a brief analysis of operational security. Or perhaps secondary divisions of a much larger organization with shared infrastructure and developers are «running» these campaigns.

Very few details are known at present. However, RSA researchers noted that detecting the infrastructure and the behavior that results from these tools may be more important when proactive defense constantly fails.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS