Monday, January 27, 2025
HomeCyber Security NewsTA505 Hackers Group Modifies Remote Admin Tool as a Weaponized Hacking Tool...

TA505 Hackers Group Modifies Remote Admin Tool as a Weaponized Hacking Tool To Attack Victims in the U.S, APAC, Europe

Published on

SIEM as a Service

Follow Us on Google News

Threat actors from TA505 hacking group conducting new wave attack by modifying the legitimate remote admin tool to Weaponized hacking tool that targets retailers in the U.S, and various financial institutions from Europe, APAC and LATAM.

TA505 hacking group believed to reside in Russia and the threat actors from this group involved in various high profile cyber attacks including infamous Dridex, Locky ransomware, ServHelper malware, FlawedAmmyy, delivered through malicious email campaigns.

This organized cybercrime group is targeting victims mainly for financial motivation by gaining access to their system to perform fraudulent financial Transaction.

In order to achieve these goals, Threat actors abusing remote manipulator system, a Russian based legitimate remote admin tool which is available for the commercial version and free version for non-commercial purposes.

RMS Tool in Underground Market

The cracked version of RMS tool Selling in underground forums which are being obtained by TA505 threat actors and using its feature including a remote control with multi-monitor support, task manager, file transfer, command line interface, network mapping capabilities, webcam and microphone access which all are common traits of well developed Remote Access Trojan.

Most of the Remote Access Trojan is capable of communicating with its operator through the command & control server. Similarly, RMS included an “ID-Internet” feature that helps to communicate with the developer’s server to send a notification via email which is being used by less sophisticated threat actors.

Attacker linked these feature with an ability to install and operate the tool silently, that makes it as the best solution for both sophisticated and unsophisticated threat actors.

But it favors highly sophisticated threat actors like TA505 by supporting “self-hosting option” which allows them to configure their own Remote Utility (RU) server.

According to cyberit report, This RU support three roles that can be deployed individually or together, although one by one, the Relay server would likely be utilized in nefarious implementations.

This Relay severs act as an intermediatory with compromised RMS clients calling home to it and identifying themselves with their “internet-ID” facilitating communications that allows firewall and NAT devices to be bypassed.

Infection Process

Attackers deliver a spear-phishing campaign with attached lure documents and trick victims to open it by utilizing with legitimate conversation, logo, terminology.

Once victims open the documents, instruct them to disable the security controls to execute the macro, which attempts to download malicious payload from the attackers by communicating through their command & control infrastructure.

C2 server domain mostly posted as legitimate domains but its slightly misspelled that related to cloud, Microsoft Office 365.

Initial malware downloader is more sophisticated and robust that mainly used to gather the other component including remote access trojan, legitimate RMS tool, shell scripts and servers to infect the target system to steal the financial data.

You can also read the RMS tool configuration steps, technical details about the infection and indicators of compromise here.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep yourself updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...

GitHub Vulnerability Exposes User Credentials via Malicious Repositories

A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...