A versatile Java-based RAT that is capable of keylogging and credential theft from browsers and email clients emerged in 2020 that is dubbed “STRRAT.”
The most recent updated version of STRRAT evolved dramatically, and since its discovery, it has been observed that it now does the following things:-
A new technique that involves two string obfuscation methods has been recently identified by the cybersecurity researchers at Cyble Research And Intelligence Labs (CRIL) to distribute STRRAT (version 1.6).
With a spam email posing as an electronic company, the infection chain begins, and here the email includes a PDF invoice attachment sent to the target.
When the attached PDF is opened it displays a download image that prompts the user to click on it, which initiates the download of “Invo-0728403.zip” from the following URL:-
Downloaded Zip holds encrypted STRRAT payload in JavaScript. Upon execution, JS decrypts the payload, placing “lypbtrtr.txt” in the following directory:-
File type check reveals a disguised JAR (zip) file that extracts the “carLambo” folder and META-INF with classes, resources, and MANIFEST.MF which ensures it is “STRRAT malware.
The analysis of the latest variant of STRRAT malware shows class name modifications and two string obfuscators (Allatori, ZKM) used, unlike the prior version that used only “Allatori.”
Since March 2023, the STRRAT malware (version 1.6) is actively distributed through multiple infection chains, and not only that in the wild more than 70 samples were detected.
For persistence, it sets the “Skype” task scheduler entry, and STRRAT 1.6 stores C&C server info in an encrypted Base64-encoded config.txt file with AES encryption, as in previous versions.
Here below we have mentioned the browsers that are targeted:-
Here below we have mentioned the email clients that are targeted:-
Here below we have mentioned all the recommendations that are offered by the security analysts:-
The VIPKeyLogger infostealer, exhibiting similarities to the Snake Keylogger, is actively circulating through phishing campaigns. …
INTERPOL has called for the term "romance baiting" to replace "pig butchering," a phrase widely…
Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT," which…
A new cyber campaign by the advanced persistent threat (APT) group Earth Koshchei has brought…
Recent research has linked a series of cyberattacks to The Mask group, as one notable…
RiseLoader, a new malware family discovered in October 2024, leverages a custom TCP-based binary protocol…