Thursday, September 15, 2022

Hackers are reviving a long-forgotten malware to help evade detection

A known Chinese threat actor is recycling old malware, in an attempt to evade detection, cut down on costs, and send researchers on a wild goose chase. 

A report from Symantec says the group, known as Webworm, has used at least three ancient malware variants (and by “ancient”, we mean from 2008 - 2017), modified them a little bit, and then tested them out against IT service providers in Asia to see how they work. 

Given the malware’s age, they sometimes manage to fly under antivirus solutions’ radars, they added. 

Stealthy RATs

The first one is called Trochilus RAT, in circulation since at least 2015, and freely available on GitHub. 

It was first discovered attacking people visiting a Myanmar website. Webworm tweaked it so that it can load its configuration from a file by checking in a set of hardcoded directories. It was also said to have the ability to move laterally across endpoints in the target network, for better access. The second one is 9002 RAT, a stealthy remote access trojan that’s now gotten better encryption for its communication protocol, which made it even more difficult to detect. 

Finally, the third is called Gh0st RAT, a 14-year-old trojan that now comes with “several layers of obfuscation, UAC bypassing, shellcode unpacking, and in-memory launch”. 

While it’s difficult to know exactly which threat actor is behind Webworm’s revival, Symantec seems to believe it’s the same group as Space Pirates - a Chinese threat actor discovered by Positive Technologies in May this year. Back then, Positive Technologies analyzed Gh0st RAT and named it Deed RAT. 

In any case, Webworm is a known cybercriminal group that’s been in operation since at least 2017. In the past, the group has been linked with various attacks on IT firms, aerospace organizations, as well as electrical energy providers in Russia, Georgia, and Mongolia. 

Via: BleepingComputer



from TechRadar - All the latest technology news https://ift.tt/BdK23gf

No comments:

Post a Comment

I tried bringing my memories to life with AI and found it works better with dogs than with human hands

MyHeritage gained a lot of attention for turning old photos into videos with its Deep Nostalgia technology in 2024, and they're also th...