Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Cybercriminals deploy VCURMS and STRRAT Trojans via AWS and GitHub
    Cyber Security

    Cybercriminals deploy VCURMS and STRRAT Trojans via AWS and GitHub

    techempireBy techempire3 Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 13, 2024Editorial DepartmentPhishing Attacks/Threat Intelligence

    VCURMS and STRRAT Trojans

    New phishing campaigns have been observed delivering remote access Trojans (RATs) such as VCURMS and STRRAT via Java-based malicious downloaders.

    “Attackers store malware on public services such as Amazon Web Services (AWS) and GitHub, and use commercial protection programs to avoid detection of the malware,” said Yurren Wan, a researcher at Fortinet FortiGuard Labs.

    An unusual aspect of the campaign was VCURMS’ use of the Proton Mail email address (“sacriliage@proton[.]me”) is used to communicate with command and control (C2) servers.

    The attack chain begins with a phishing email urging the recipient to click a button to verify payment information, which results in the download of a malicious JAR file (“Payment-Advice.jar”) hosted on AWS.

    Internet security

    Executing the JAR file causes two additional JAR files to be retrieved, which are then run separately to launch the two Trojans.

    In addition to sending an email containing a “Hey Master, I’m online” message to an attacker-controlled address, VCURMS RAT also periodically checks the mailbox for emails with specific subject lines to extract the commands to be executed from the message body .

    This includes using cmd.exe to execute arbitrary commands, collect system information, search and upload files of interest, and download other information stealers and keylogger modules from the same AWS endpoint.

    This infostealer is capable of stealing sensitive data, credentials, cookies from applications such as Discord and Steam, as well as autofill data from various web browsers, screenshots, and the hardware and network of a large number of infected hosts Information.

    VCURMS is said to be similar to another Java-based information-stealing program codenamed Rude Stealer that emerged late last year. STRRAT, on the other hand, has been spotted in the wild since at least 2020, often distributed as fraudulent JAR files.

    Internet security

    “STRRAT is a RAT built using Java that has a wide range of capabilities, such as serving as a keylogger and extracting credentials from browsers and applications,” Wan noted.

    The revelation comes as Darktrace revealed a novel phishing campaign that leverages the Dropbox cloud storage service to send automated emails via “no-reply@dropbox”[.]com” to spread fake links that mimic the Microsoft 365 login page.

    “The email itself contains a link that leads users to a PDF file hosted on Dropbox that appears to be named after a partner of the organization,” the company said. Suspicious links to domains seen in customer environments, ‘mmv-security'[.]top. ‘”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.