Tuesday, April 15, 2025
HomeComputer SecurityNew Malware Attack Drops Double Remote Access Trojan in Windows to Steal...

New Malware Attack Drops Double Remote Access Trojan in Windows to Steal Chrome, Firefox Browsers Data

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malware campaign that drops two different Remote Access Trojan(RAT) on targeted Windows systems and steal sensitive information from popular browsers such as Chrome and Firefox.

The samples that uncovered by Fortinet researchers drop the RevengeRAT and WSHRAT malware and it has various obfuscation functionalities that use the various stage to maintain the persistence.

RAR’s Infection Process

RevengeRAT

The RAT has infected the victims by utilizing the different stages. When opening the malicious sample file, it contained JavaScript code in a text editor with encoded data. Once decoded its drops the VBScript code is responsible for drop the next stage of malware.

- Advertisement - Google News

The dropper then later download the second stage of malicious downloader( “A6p.vbs” file) from the external website which also contains an obfuscated strings to avoid detection.

If the downloader script will be successfully executed then it establishes a connection with command and control server to download the script file “Microsoft.vbs”.and it saved as “MICROSOFT.VBS” in the %TEMP% folder.

Remote Access Trojan

According to Fortinet research “The script properly invokes a number of composed PowerShell commands to bypass the interpreter’s execution policy and to hide its presence, thereby bypassing the “-ExecutionPolicy Bypass -windowstyle hidden -noexit -Command” parameters”

Once the RAT successfully deployed, it connects to two C&C servers. But the two C&C servers had been shut down during the analysis. So researchers decided to set up a fake C2 server to analyze the sample.

Once the connection to the C&C server is established, it collects information from the victim’s system that will be sent to its server.

WSH RAT 

The infection chain with this WSH RAT used the same code from MICROSOFT.VBS in the GXxdZDvzyH.vbs script. But the payload in complete different that encoded in base-64.

Researcher digging deep and analyzed the code and confirms that it has 29 functions to perform different tasks including entrenchment, persistency, and data processing to stealing and exfiltration.

Also, WSH RAT make use of a total of 26 commands of following

“disconnect”, “reboot”, “shutdown”, “execute”, “install-sdk”, “get-pass”, “get-pass-offline”, “update”, “uninstall”, “up-n-exec”, “bring-log”, “down-n-exec”, “filemanager”, “rdp”, “keylogger”, “offline-keylogger”, “browse-logs”, “cmd-shell”, “get-processes”, “disable-uac”, “check-eligible”, “force-eligible”, “elevate”, “if-elevate”, “kill-process”, and “sleep”.

WSH RAT’s main focus is to steal the data popular browser such as Chrome and Mozilla Firefox including FoxMail software.

“The script generates a properly formatted HTTP request that contains information related to the infected computer, and uses the “User-Agent:” header as a mechanism to exfiltrate it,” Fortinet said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

The Future of Authentication: Moving Beyond Passwords

Traditional passwords have been the cornerstone of digital security for six decades, but their...

CentreStack 0-Day Exploit Enables Remote Code Execution on Web Servers

A critical 0-day vulnerability has been disclosed in CentreStack, a popular enterprise cloud storage...

Over 100,000 WordPress Plugin Vulnerability Exploited Just 4 Hours After Disclosure

Over 100,000 WordPress websites have been exposed to a critical security vulnerability, following the...

Hackers Use Microsoft Teams Chats to Deliver Malware to Windows PCs

A sophisticated cyberattack campaign has emerged, leveraging Microsoft Teams chats to infiltrate Windows PCs...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Use Microsoft Teams Chats to Deliver Malware to Windows PCs

A sophisticated cyberattack campaign has emerged, leveraging Microsoft Teams chats to infiltrate Windows PCs...

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...