Home Security Hackers Utilizing Rogue Variations of KeePass and SolarWinds Software program to Distribute RomCom RAT

Hackers Utilizing Rogue Variations of KeePass and SolarWinds Software program to Distribute RomCom RAT

by crpt os


The operators of RomCom RAT are continuing to evolve their campaigns with rogue versions of software such as SolarWinds Network Performance Monitor, KeePass password manager, and PDF Reader Pro.

Targets of the operation consist of victims in Ukraine and select English-speaking countries like the U.K.

“Given the geography of the targets and the current geopolitical situation, it’s unlikely that the RomCom RAT threat actor is cybercrime-motivated,” the BlackBerry Threat Research and Intelligence Team said in a new analysis.

The latest findings come a week after the Canadian cybersecurity company disclosed a spear-phishing campaign aimed at Ukrainian entities to deploy a remote access trojan called RomCom RAT.

The unknown threat actor has also been observed leveraging trojanized variants of Advanced IP Scanner and pdfFiller as droppers to distribute the implant.

The latest iteration of the campaign entails setting up decoy lookalike websites with a similar domain name, followed by uploading a malware-laced installer bundle of the malicious software, and then sending phishing emails to targeted victims.

Fake Keypass website
Fake Keypass website
Fake SolarWinds website
Fake SolarWinds website

“While downloading a free trial from the spoofed SolarWinds site, a legitimate registration form appears,” the researchers explained.

“If filled out, real SolarWinds sales personnel might contact the victim to follow up on the product trial. That technique misleads the victim into believing that the recently downloaded and installed application is completely legitimate.”

CyberSecurity

It’s not just SolarWinds software. Other impersonated versions involve the popular password manager KeePass and PDF Reader Pro, including in the Ukrainian language.

The use of RomCom RAT has also been linked to threat actors associated with the Cuba ransomware and Industrial Spy, according to Palo Alto Networks Unit 42, which is tracking the ransomware group under the constellation-themed moniker Tropical Scorpius.

Given the interconnected nature of the cybercriminal ecosystem, it’s not immediately evident if the two sets of activities share any connections or if the malware is offered for sale as a service to other threat actors.





Source link

Related Articles

xxxanti beeztube.mobi hot sexy mp4 menyoujan hentaitgp.net jason voorhees hentai indian soft core chupatube.net youjzz ez2 may 8 2023 pinoycinema.org ahensya ng pamahalaan pakistani chut ki chudai pimpmovs.com www xvedio dost ke papa zztube.mobi 300mbfilms.in صور مص الزب arabporna.net نهر العطش لمن تشعر بالحرمان movierulz plz.in bustyporntube.info how to make rangoli video 穂高ゆうき simozo.net 四十路五十路 ロシアav javvideos.net 君島みお 無修正 افلام سكس في المطبخ annarivas.net فيلم سكس قديم rashmi hot videos porncorn.info audiosexstories b grade latest nesaporn.pro high school girls sex videos real life cam eroebony.info painfull porn exbii adult pics teacherporntrends.com nepali school sex