Friday, February 14, 2025
HomeComputer SecurityNew Malware Attack Drops Double Remote Access Trojan in Windows to Steal...

New Malware Attack Drops Double Remote Access Trojan in Windows to Steal Chrome, Firefox Browsers Data

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malware campaign that drops two different Remote Access Trojan(RAT) on targeted Windows systems and steal sensitive information from popular browsers such as Chrome and Firefox.

The samples that uncovered by Fortinet researchers drop the RevengeRAT and WSHRAT malware and it has various obfuscation functionalities that use the various stage to maintain the persistence.

RAR’s Infection Process

RevengeRAT

The RAT has infected the victims by utilizing the different stages. When opening the malicious sample file, it contained JavaScript code in a text editor with encoded data. Once decoded its drops the VBScript code is responsible for drop the next stage of malware.

The dropper then later download the second stage of malicious downloader( “A6p.vbs” file) from the external website which also contains an obfuscated strings to avoid detection.

If the downloader script will be successfully executed then it establishes a connection with command and control server to download the script file “Microsoft.vbs”.and it saved as “MICROSOFT.VBS” in the %TEMP% folder.

Remote Access Trojan

According to Fortinet research “The script properly invokes a number of composed PowerShell commands to bypass the interpreter’s execution policy and to hide its presence, thereby bypassing the “-ExecutionPolicy Bypass -windowstyle hidden -noexit -Command” parameters”

Once the RAT successfully deployed, it connects to two C&C servers. But the two C&C servers had been shut down during the analysis. So researchers decided to set up a fake C2 server to analyze the sample.

Once the connection to the C&C server is established, it collects information from the victim’s system that will be sent to its server.

WSH RAT 

The infection chain with this WSH RAT used the same code from MICROSOFT.VBS in the GXxdZDvzyH.vbs script. But the payload in complete different that encoded in base-64.

Researcher digging deep and analyzed the code and confirms that it has 29 functions to perform different tasks including entrenchment, persistency, and data processing to stealing and exfiltration.

Also, WSH RAT make use of a total of 26 commands of following

“disconnect”, “reboot”, “shutdown”, “execute”, “install-sdk”, “get-pass”, “get-pass-offline”, “update”, “uninstall”, “up-n-exec”, “bring-log”, “down-n-exec”, “filemanager”, “rdp”, “keylogger”, “offline-keylogger”, “browse-logs”, “cmd-shell”, “get-processes”, “disable-uac”, “check-eligible”, “force-eligible”, “elevate”, “if-elevate”, “kill-process”, and “sleep”.

WSH RAT’s main focus is to steal the data popular browser such as Chrome and Mozilla Firefox including FoxMail software.

“The script generates a properly formatted HTTP request that contains information related to the infected computer, and uses the “User-Agent:” header as a mechanism to exfiltrate it,” Fortinet said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code

A newly discovered vulnerability in WinZip, a popular file compression and archiving utility, has...

New Microsoft Windows GUI 0-Day Vulnerability Actively Exploited in the Wild

A newly discovered vulnerability in Microsoft Windows, identified by ClearSky Cyber Security, is reportedly...

Burp Suite Professional / Community 2025.2 Released With New Built-in AI Integration

PortSwigger has announced the release of Burp Suite Professional and Community Edition 2025.2, introducing...

Arbitrary File Upload Vulnerability in WordPress Plugin Let Attackers Hack 30,000 Website

A subgroup of the Russian state-sponsored hacking group Seashell Blizzard, also known as Sandworm,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New Malware Abuses Microsoft Graph API to Communicate via Outlook

A newly discovered malware, named FINALDRAFT, has been identified leveraging Microsoft Outlook as a...

Winnti Hackers Attacking Japanese Organisations with New Malware

The China-based Advanced Persistent Threat (APT) group known as the Winnti Group, also referred...

Threat Actors Exploiting DeepSeek’s Popularity to Deploy Malware

The meteoric rise of DeepSeek, a Chinese AI startup, has not only disrupted the...