Malicious software uses Gmail to receive commands and filter user data
The version of ComRAT v4 (the author of this malware called 'Chinch') uses a whole new code base and is much more complex than previous generations. According to ESET security researchers, the main purpose of ComRAT is to detect, steal, filter personal documents, sometimes even deploy the .NET implementation to interact with the MS database. SQL Server on the victim machine contains documents of the organization.
ComRAT v4's 'Mail' mode works to read valid email addresses and temporary files (cookies) stored at VFS (Virtual File System), connect to Gmail's basic HTML interface, analyze The syntax of the mailbox is on the HTML page and then the email subject list matches the file 'subject.str' on VFS.
For each email that meets the above criteria, ComRAT will download the available attachment and delete the email to avoid repeating it a second time. Whether containing the same format as the Word file (.docx) or Excel (.xlsx) in the name, the actual attachments are not document files but are encrypted binary data files containing specialized executables. especially reading / writing files, executing additional processes, collecting activity history, etc.
The results of the execution commands are then encrypted and stored as an attachment and sent in an email to the destination address available in the VFS file.
Based on one month's Gmail distribution patterns, ESET said the guys behind this campaign operate in the UTC + 3 or UTC + 4 time zone.
'ComRAT v4 was first discovered in 2017 and as of January 2020 is still active,' security expert at ESET company shared on THN. The company found that there were at least three targets targeted by the malware, including the Foreign Ministry of two Western European countries and a Caucasian parliament.
Backdoor ComRAT has long been used by the Turla APT team. The group, also known as Snake, has been operating for more than a decade with a 'track record' of offensive campaigns targeting embassies and military organizations from around 2004 or earlier.
Turla's espionage began with Agent.BTZ in 2007, later evolving into ComRAT - a remote control tool to add the ability to steal information from the local network. It was the early versions of Agent.BTZ that infiltrated the US military network in the Middle East in 2008. In the last few years, Turla was determined to be behind the attacks on the French Armed Forces (FAF) network. ) 2018 and the Austrian Foreign Ministry earlier this year.
3.5 ★ | 2 Vote
You should read it
- Information security: Data encryption - not enough!
- A hacker in the United Kingdom found a way to temporarily encrypt the WannaCry malware
- Appearing dangerous Android malicious code specializing in stealing chat content on Facebook Messenger, Skype ...
- Hackers fake Windows 11 download page to spread malicious code
- Most Android anti-virus software cannot detect malicious APK files
- Dozens of Android applications are infected with malicious code
- Android software specialized in stealing bank passwords, copying keystrokes
- Lukitus Guide to preventing extortion malicious code
May be interested
- Detecting a Chrome extension infected with malicious code, stealing the password and the user's e-wallet keyzdnet, mega.nz reports - chrome's data sharing extension has been infected with malicious code. this malicious code has the ability to collect information about visitors' websites, account names, passwords and other data.
- Guide to Automatic Filter and Filter detailed data in excelto search and create small data tables that meet some conditions as required into big tables, we have to filter those data.
- Filter data in Excel with Advanced Filterin the process of working with data tables in excel, the filtering of data in the data tables is very necessary and often done. there are many ways to filter and functions to help you filter data in data tables.
- Advanced data filtering in Excelinstructions on how to filter advanced data in excel. data filter (automatic data filtering) allows you to filter data only on a single column or data field -> so it is limited when using data. excel supports the advanced filter feature that allows you to filter
- MS Excel 2007 - Lesson 8: Sort and Filtersort and filter are features that allow you to manipulate data in a spreadsheet based on standards. to sort data and filter data in excel 2007 you will use the sort & filter feature. below tipsmake.com will guide you how to filter data, arrange data with this feature in excel 2007.
- How to receive email notifications from Gmail on iPhonedon't want to be bothered by unimportant emails? you can change email notification settings in gmail on iphone / ipad, mac, windows pc or linux to get rid of this situation. in other words, gmail gives you the option to receive notifications only when there are important emails.
- A series of malicious applications that collect user data, delete immediately if you are installingsecurity experts at mcafee have discovered a new type of malicious code that has entered the google play store through 60 different applications, called goldoson.
- How to filter data in Excelyour excel spreadsheet has a lot of data, so it's easy to process and search the data in your table. filter data by conditions, criteria you give, you will shorten the search time and data processing
- Instructions on how to send and receive email with Gmailwhen you have successfully registered a gmail account, how to use send and receive it? the following article, tipsmake will guide you to read details on how to send and receive email offline!
- How to receive Gmail notifications on Desktop screen?receiving gmail notifications on the desktop is one of gmail's cool and new features. if you are a regular checker of gmail, this feature is really useful for you.