Thursday, January 2, 2025
HomeCyber AttackHackers Deliver Updated STRRAT Malware Using Weaponized PDF Files

Hackers Deliver Updated STRRAT Malware Using Weaponized PDF Files

Published on

SIEM as a Service

A versatile Java-based RAT that is capable of keylogging and credential theft from browsers and email clients emerged in 2020 that is dubbed “STRRAT.”

The most recent updated version of STRRAT evolved dramatically, and since its discovery, it has been observed that it now does the following things:-

  • Incorporates “Crimson” Ransomware module.
  • Deploys a multitude of infection chains.

A new technique that involves two string obfuscation methods has been recently identified by the cybersecurity researchers at Cyble Research And Intelligence Labs (CRIL) to distribute STRRAT (version 1.6).

- Advertisement - SIEM as a Service

Malware Infection chain

With a spam email posing as an electronic company, the infection chain begins, and here the email includes a PDF invoice attachment sent to the target.

Infection chain (Source – Cyble)

When the attached PDF is opened it displays a download image that prompts the user to click on it, which initiates the download of “Invo-0728403.zip” from the following URL:-

  • hxxps://tatchumbemerchants[.]co.ke/Invo-0728403[.]zip
Malicious PDF attachment (Source – Cyble)

Downloaded Zip holds encrypted STRRAT payload in JavaScript. Upon execution, JS decrypts the payload, placing “lypbtrtr.txt” in the following directory:-

  • \AppData\Roaming

File type check reveals a disguised JAR (zip) file that extracts the “carLambo” folder and META-INF with classes, resources, and MANIFEST.MF which ensures it is “STRRAT malware.

Content of JAR file (Source – Cyble)

The analysis of the latest variant of STRRAT malware shows class name modifications and two string obfuscators (Allatori, ZKM) used, unlike the prior version that used only “Allatori.”

Distribution & Persistance

Since March 2023, the STRRAT malware (version 1.6) is actively distributed through multiple infection chains, and not only that in the wild more than 70 samples were detected.

For persistence, it sets the “Skype” task scheduler entry, and STRRAT 1.6 stores C&C server info in an encrypted Base64-encoded config.txt file with AES encryption, as in previous versions.

Here below we have mentioned the browsers that are targeted:-

  • Chrome
  • Firefox
  • Internet Explorer 

Here below we have mentioned the email clients that are targeted:-

  • Outlook
  • Thunderbird
  • Foxmail

Recommendations

Here below we have mentioned all the recommendations that are offered by the security analysts:-

  • Always use strong email filter solutions.
  • Make sure to verify the links and attachments before opening them.
  • Always use robust endpoint security solutions. 
  • Keep security tools updated with the latest available patches and updates.
  • Implement URL filtering to block malicious sites.
  • Conduct regular employee cybersecurity training.

IoCs

IoCs (Source – Cyble)
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

PoC Exploit Released For Critical Windows LDAP RCE Vulnerability

The CVE-2024-49112 vulnerability in Windows LDAP allows remote code execution on unpatched Domain Controllers,...

New PLAYFULGHOST Malware Hacking Devices To Remotely Capture Audio Recordings

PLAYFULGHOST, a Gh0st RAT variant, leverages distinct traffic patterns and encryption, which spread via...

Researchers Uncover Phishing-As-A-Service Domains Associated With Tycoon 2FA

The Tycoon 2FA platform is a Phishing-as-a-Service (PhaaS) tool that enables cybercriminals to easily...

Windows 11 BitLocker Encryption Bypassed to Extract Full Volume Encryption Keys

A cybersecurity researcher has demonstrated a method to bypass BitLocker encryption on Windows 11...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

PoC Exploit Released For Critical Windows LDAP RCE Vulnerability

The CVE-2024-49112 vulnerability in Windows LDAP allows remote code execution on unpatched Domain Controllers,...

New PLAYFULGHOST Malware Hacking Devices To Remotely Capture Audio Recordings

PLAYFULGHOST, a Gh0st RAT variant, leverages distinct traffic patterns and encryption, which spread via...

Researchers Uncover Phishing-As-A-Service Domains Associated With Tycoon 2FA

The Tycoon 2FA platform is a Phishing-as-a-Service (PhaaS) tool that enables cybercriminals to easily...