Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

BitRat Malware Gnaws at Victims With Bank Heist Data

Altszn.com by Altszn.com
January 6, 2023
in Monero
0
BitRat Malware Gnaws at Victims With Bank Heist Data
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Threat actors are using data stolen from a Colombian bank as a lure in what appears to be a malicious campaign aimed at spreading the BitRAT malware, researchers have found. The activity demonstrates the evolution of how attackers are using commercial, off-the-shelf malware in advanced threat scenarios, they said.

Researchers at IT security and compliance firm Qualys were investigating “multiple lures” for BitRAT when they identified that the infrastructure of a Colombian cooperative bank had been hijacked. Attackers were using sensitive data gleaned from that compromise to try to capture victims, they reported in a blog post published Jan. 3.

“While digging deeper into the infrastructure, we identified logs that point to the usage of the tool sqlmap to find potential SQLi faults, along with actual database dumps,” Akshat Pradhan, senior engineer of threat research at Qualys, wrote in the post.

Overall, threat actors leaked 4,18,777 rows of sensitive data from the bank’s customers, including details such as Colombian national ID numbers — called “Cedula” numbers — as well as email addresses, phone numbers, customer names, payment records, salary, home addresses, and other data, researchers said.

So far, researchers have not seen the data dumped on any hacker forums or Dark Web sites, and are following standard breach-disclosure guidelines as they further investigate, they said.

A Commercial RAT With a Long Tail

Threat actors began marketing BitRAT on underground cybercriminal markets starting in February 2021. The RAT is notorious for its social media presence and its relatively low price of $20, which makes it popular among cybercriminals, researchers said.

Key capabilities of BitRAT include: data exfiltration, execution of payloads with bypasses, distributed denial of service (DDoS), keylogging, webcam and microphone recording, credential theft, Monero mining, and running tasks for process, file, and software, among others.

BitRAT is an example of how the use of commercial RATs has evolved not only with new capabilities for propagation, but also by harnessing the use of legitimate infrastructures to host malicious payloads, Pradhan said. This is something that enterprises now need to account for in their respective security defense postures, he noted.

To that end, researchers advised that all organizations employ endpoint detection and response (EDR) solutions to detect malware such as BitRAT as it inserts itself into a network endpoint, they said. Functions like asset management, vulnerability detection, policy compliance, patch management, and file-integrity monitoring capabilities across a system are key for combating malware like this, they added.

Enterprises should also implement external attack surface management solutions, which allow for continuous monitoring and reduction of the entire enterprise attack surface — including internal and Internet-facing assets and discover previously unidentified exposures — to counter evolving threats, researchers said.

Anatomy of the BitRAT

Researchers found and analyzed a cache of Excel sheets — all authored by “Administrator” — being used as lures for a BitRAT campaign, with data from the tables being reused in Excel maldocs as well being included in the database dump, they said.

“The Excel contains a highly obfuscated macro that will drop an .inf payload and execute it,” Pradhan wrote in the post. “The .inf payload is segmented into hundreds of arrays in the macro.”

A de-obfuscation routine performs arithmetic operations on the arrays to rebuild the payload once it’s ready for execution, with the macro then writing the payload to “temp” and executing it via a file called advpack.dll, he said.

The macro itself also includes a hex-encoded, second-stage .dll payload that is decoded via certutil, written to “%temp%\,” and executed by the command “rundll32,” researchers found. After this process is executed, the temp files are then deleted, they said.

It’s this .dll file that uses various anti-debugging techniques to download and execute the final BitRAT payload. The file also uses the WinHTTP library to download BitRAT-embedded payloads from a GitHub repository created in mid-November by a “throwaway” account to the “%temp%” directory, Pradhan wrote.

In the final stage of BitRAT execution, the .dll uses WinExec to start the “%temp%” payload and exits. To maintain persistence on a user’s machine, the BitRAT sample starts and then relocates the loader to the user’s startup, the researchers said.



Read More: news.google.com

Tags: bankBitRATdataGnawsheistMalwareMoneroVictims
ADVERTISEMENT

Recent

Polygon co-founder steps down, says he can no longer give his best

Polygon co-founder steps down, says he can no longer give his best

May 24, 2025
Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

May 23, 2025
'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

May 23, 2025

Categories

  • Bitcoin (4,677)
  • Blockchain (11,077)
  • Crypto (9,015)
  • Dark Web (493)
  • DeFi (8,234)
  • Ethereum (4,716)
  • Metaverse (7,147)
  • Monero (268)
  • NFT (1,276)
  • Solana (4,971)
  • Web3 (20,248)
  • Zcash (479)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    Polygon co-founder steps down, says he can no longer give his best

    Polygon co-founder steps down, says he can no longer give his best

    May 24, 2025
    Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

    Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

    May 23, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 108,221.00
    • ethereumEthereum (ETH) $ 2,550.57
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.34
    • bnbBNB (BNB) $ 667.71
    • solanaSolana (SOL) $ 175.03
    • usd-coinUSDC (USDC) $ 0.999794
    • dogecoinDogecoin (DOGE) $ 0.228294
    • cardanoCardano (ADA) $ 0.760590
    • tronTRON (TRX) $ 0.272845
    • staked-etherLido Staked Ether (STETH) $ 2,547.53
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,026.00
    • suiSui (SUI) $ 3.68
    • hyperliquidHyperliquid (HYPE) $ 33.06
    • wrapped-stethWrapped stETH (WSTETH) $ 3,067.10
    • chainlinkChainlink (LINK) $ 15.78
    • avalanche-2Avalanche (AVAX) $ 23.19
    • stellarStellar (XLM) $ 0.290462
    • bitcoin-cashBitcoin Cash (BCH) $ 429.71
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.81
    • hedera-hashgraphHedera (HBAR) $ 0.192080
    • the-open-networkToncoin (TON) $ 3.02
    • litecoinLitecoin (LTC) $ 96.55
    • wethWETH (WETH) $ 2,545.03
    • moneroMonero (XMR) $ 389.35
    • polkadotPolkadot (DOT) $ 4.60
    • usdsUSDS (USDS) $ 0.999817
    • bitget-tokenBitget Token (BGB) $ 5.53
    • wrapped-eethWrapped eETH (WEETH) $ 2,717.41
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998092
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.784696
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 31.81
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,166.00
    • aaveAave (AAVE) $ 259.26
    • bittensorBittensor (TAO) $ 426.76
    • daiDai (DAI) $ 0.999921
    • uniswapUniswap (UNI) $ 6.10
    • nearNEAR Protocol (NEAR) $ 2.83
    • aptosAptos (APT) $ 5.39
    • jito-staked-solJito Staked SOL (JITOSOL) $ 210.79
    • okbOKB (OKB) $ 52.14
    • ondo-financeOndo (ONDO) $ 0.951741
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.096625
    • kaspaKaspa (KAS) $ 0.108785
    • ethereum-classicEthereum Classic (ETC) $ 18.61
    • internet-computerInternet Computer (ICP) $ 5.29
    • bitcoinBitcoin (BTC) $ 108,221.00
    • ethereumEthereum (ETH) $ 2,550.57
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.34
    • bnbBNB (BNB) $ 667.71
    • solanaSolana (SOL) $ 175.03
    • usd-coinUSDC (USDC) $ 0.999794
    • dogecoinDogecoin (DOGE) $ 0.228294
    • cardanoCardano (ADA) $ 0.760590
    • tronTRON (TRX) $ 0.272845
    • staked-etherLido Staked Ether (STETH) $ 2,547.53
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,026.00
    • suiSui (SUI) $ 3.68
    • hyperliquidHyperliquid (HYPE) $ 33.06
    • wrapped-stethWrapped stETH (WSTETH) $ 3,067.10
    • chainlinkChainlink (LINK) $ 15.78
    • avalanche-2Avalanche (AVAX) $ 23.19
    • stellarStellar (XLM) $ 0.290462
    • bitcoin-cashBitcoin Cash (BCH) $ 429.71
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • leo-tokenLEO Token (LEO) $ 8.81
    • hedera-hashgraphHedera (HBAR) $ 0.192080
    • the-open-networkToncoin (TON) $ 3.02
    • litecoinLitecoin (LTC) $ 96.55
    • wethWETH (WETH) $ 2,545.03
    • moneroMonero (XMR) $ 389.35
    • polkadotPolkadot (DOT) $ 4.60
    • usdsUSDS (USDS) $ 0.999817
    • bitget-tokenBitget Token (BGB) $ 5.53
    • wrapped-eethWrapped eETH (WEETH) $ 2,717.41
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998092
    • pepePepe (PEPE) $ 0.000014
    • pi-networkPi Network (PI) $ 0.784696
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 31.81
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,166.00
    • aaveAave (AAVE) $ 259.26
    • bittensorBittensor (TAO) $ 426.76
    • daiDai (DAI) $ 0.999921
    • uniswapUniswap (UNI) $ 6.10
    • nearNEAR Protocol (NEAR) $ 2.83
    • aptosAptos (APT) $ 5.39
    • jito-staked-solJito Staked SOL (JITOSOL) $ 210.79
    • okbOKB (OKB) $ 52.14
    • ondo-financeOndo (ONDO) $ 0.951741
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.096625
    • kaspaKaspa (KAS) $ 0.108785
    • ethereum-classicEthereum Classic (ETC) $ 18.61
    • internet-computerInternet Computer (ICP) $ 5.29