Home Malware North Korean state-sponsored hacker group Lazarus adds new RAT to its malware toolset

North Korean state-sponsored hacker group Lazarus adds new RAT to its malware toolset

Source Link

Security researchers have discovered a new remote access Trojan (RAT) being used in attack campaigns this year by Lazarus, a threat actor tied to the North Korean government. The new RAT has been used alongside other malware implants attributed to Lazarus and it’s mainly used in the first stages of an attack.

Dubbed MagicRAT, the new Lazarus malware program was developed using Qt, a framework commonly used to develop graphical user interfaces for cross-platform applications. Since the Trojan doesn’t have a GUI, researchers from Cisco Talos believe the reason for using Qt was to make detection harder.

“Talos believes that the objective was to increase the complexity of the code, thus making human analysis harder,” the Cisco researchers said in their report. “On the other hand, since there are very few examples (if any) of malware programmed with Qt Framework, this also makes machine learning and heuristic analysis detection less reliable.”

How the MagicRAT malware works

In addition to using Qt classes throughout its entire codebase, MagicRAT also stores configuration data such as three encoded command-and-control URLs inside a QSettings class. Once deployed, it creates two scheduled tasks to achieve persistence at system reboot and copies a shortcut file with the name OneNote in the startup folder.

The Trojan then collects system information using command-line tools and uploads the resulting file to the C2 servers. Attackers can connect remotely to MagicRAT and obtain shell access on the system that allows them to perform additional hands-on hacking.

The researchers also found other malware payloads on the C2 servers that were hidden as GIF files. These included a lightweight port scanner and a more complex RAT called TigerRAT that has been attributed to the Lazarus group since 2021.

Copyright © 2022 IDG Communications, Inc.

Related Articles

Leave a Comment

techhipbettruvabetnorabahisbahis forumutaraftarium24eduseduedueduedueduseduseduseduedu