Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Innovative Spy Trojan Targets European Diplomatic Targets
#1
Information 
Quote:A fresh malware trojan has emerged, built from the same code base as the stealthy COMPFun remote access trojan (RAT). The malware is using spoofed visa applications to hit diplomatic targets in Europe and may be the work of the Turla APT.
 
According to researchers at Kaspersky, the fake visa application harbors code that acts as a first-stage dropper. That dropper in turn fetches the main payload, which logs the target’s location, gathers host- and network-related data, performs keylogging and takes screenshots. It also monitors USB devices and can infect them in order to spread further, and it receives commands from the command-and-control (C2) server in the form of HTTP status codes.
 
“In other words, it’s a normal full-fledged trojan that is also capable of propagating itself to removable devices,” researchers wrote in a Thursday analysis. “As in previous malware from the same authors…to exfiltrate the target’s data to the C2 over HTTP/HTTPS, the malware uses RSA encryption. To hide data locally, the trojan implements LZNT1 compression and one-byte XOR encryption.”
 
As for that “previous malware,” the code base for the new RAT is similar to a COMPFun successor known as Reductor, which Kaspersky observed last year infecting files on the fly to compromise TLS traffic. The firm attributes the new RAT to the same threat actor – which is perhaps the Turla APT.

Read more: https://threatpost.com/innovative-spy-tr...ts/155763/
[-] The following 2 users say Thank You to silversurfer for this post:
  • dinosaur07, harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Advanced SystemCare PRO 17
Advanced SystemCare ...zevish — 10:04
How to install iOS 16 or iPadOS 16 publ...
IPhone X I Just buyi...thomasan — 08:30
Brave 1.65.114
Release Channel 1....harlan4096 — 06:53
Brave Search: Answer with AI takes over,...
Brave Search's new...harlan4096 — 06:33
Waterfox G6.0.12
Waterfox G6.0.12​ ...harlan4096 — 15:56

[-]
Birthdays
Today's Birthdays
avatar (47)oapedDow
avatar (40)Sanchowogy
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo
avatar (36)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>