Friday, April 4, 2025
HomeMalwareJava-based STRRAT Malware RAT Attack Windows Users by Mimics as Ransomware

Java-based STRRAT Malware RAT Attack Windows Users by Mimics as Ransomware

Published on

SIEM as a Service

Follow Us on Google News

Recently, a new malware campaign, STRRAT has been detected by the Microsoft security team, as per the security experts, the hackers are distributing a remote access Trojan (RAT) through this malware.

This malware is stealing data from the infected systems, and not only this but the malware is remarkable, as it always conceals itself as ransomware.

The researchers at the Microsoft security team have investigated the malware and realized that this malware can work as a backdoor on every affected host. 

The operators of this malware have specifically designed this malware to steal the credentials from the infected Windows systems. However, this is not the first time when experts detected this malware, as STRRAT has been initially detected in 2020. 

And the previous technical report claims that this malware had got a wide range of functions, that helps it to steal credentials and modify all local files on the infected machines.

Bot only that even the experts at Microsoft has also claimed that the STRRAT version 1.2, is currently witnessing a massive campaign so that they can distribute its STRRAT version 1.5.

Infection chain

In this malware campaign, the threat actors have used all the negotiated email account, and the main reason behind this is to transfer different emails accordingly.

However, the emails have different messages and subjects, thus some subjects lines are like “Outgoing Payments.” Apart from this, there are many other subjects like “Accounts Payable Department”, and that’s how every email was assigned by the hackers to achieve all their desired goals.

In this campaign, the threat actors use social engineering for all payment receipts in their email subjects, and the main motive of the hackers for doing this is to motivate people so that they will click on an attached file of malicious intent, that is masked as a legitimate file.

It enables the Remote Desktop Host support and installs the open-source RDP Wrapper Library (RDPWrap) on the compromised systems to provide remote access to its operators.

Browser affected

The operators of the STRRAT can easily run commands and harvest sensitive information on the infected systems remotely, as it has the ability to log all the keystrokes on the infected systems.

To exfiltrate sensitive data like credentials and run commands remotely the operators of STRRAT can abuse the major email clients and browsers like:-

  • Mozilla Firefox
  • Internet Explorer
  • Google Chrome
  • Foxmail
  • Microsoft Outlook
  • Thunderbird

Mitigation

Moreover, the cybersecurity analysts of the Microsoft security team have also mentioned some common mitigation to bypass this malware. As told that the Microsoft 365 Defender can help the victims to bypass the STRRAT malware campaign. 

Even they have also apprehended that the hackers are keeping their bogus encryption behavior in the same signal. So, in this meantime, the threat actors are aiming to make a lump-sum amount of money in a short period of time money through extortion.

The machine learning-based protections on the Microsoft 365 Defender detect blocks the malware on endpoints and directly alert the security experts regarding the malware.

Apart from all these things, the experts have also noted that the threat actors have added more obfuscation in this malware and expanded its modular architecture.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Beware of Clickfix: ‘Fix Now’ and ‘Bot Verification’ Lures Deliver and Execute Malware

A sophisticated browser-based malware delivery method, dubbed ClickFix, has emerged as a significant threat...

DeepSeek-R1 Prompts Abused to Generate Advanced Malware and Phishing Sites

The release of DeepSeek-R1, a 671-billion-parameter large language model (LLM), has sparked significant interest...

Malicious PyPI Package Targets E-commerce Sites with Automated Carding Script

Cybersecurity researchers from Socket have exposed a malicious Python package on PyPI, named disgrasya,...

New Credit Card Skimming Campaign Uses Browser Extensions to Steal Financial Data

A newly discovered credit card skimming campaign, dubbed "RolandSkimmer," is exploiting browser extensions to...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Beware of Clickfix: ‘Fix Now’ and ‘Bot Verification’ Lures Deliver and Execute Malware

A sophisticated browser-based malware delivery method, dubbed ClickFix, has emerged as a significant threat...

DeepSeek-R1 Prompts Abused to Generate Advanced Malware and Phishing Sites

The release of DeepSeek-R1, a 671-billion-parameter large language model (LLM), has sparked significant interest...

Chinese Hackers Exploit Ivanti VPN Vulnerability to Deliver Malware Payloads

Ivanti disclosed a critical security vulnerability, CVE-2025-22457, affecting its Connect Secure (ICS) VPN appliances,...