Summary:
The threat actor known as Webworm is taking advantage of previously used RATs. The group reportedly developed customized versions of three older remote access trojans - Trochilus, Gh0st RAT and 9002 RAT, and Using them to successfully evade detection on victim networks. The re-coded malware includes Trochilus RAT, which was first detected in 2015, and Gh0st RAT which was first introduced in 2008 by GhostNet, an infamous state-sponsored threat group that some experts connected to China. A third malware known as 9002 RAT, was first observed in 2009 and was used in attacks against South Korean enterprises in 2018. It is reported that the group was conducting cyberespionage attacks against government agencies as well as energy and aerospace companies in Russia, Georgia, and Mongolia.[/subscribe_to_unlock_form]
Summary:
The threat actor known as Webworm is taking advantage of previously used RATs. The group reportedly developed customized versions of three older remote access trojans - Trochilus, Gh0st RAT and 9002 RAT, and Using them to successfully evade detection on victim networks. The re-coded malware includes Trochilus RAT, which was first detected in 2015, and Gh0st RAT which was first introduced in 2008 by GhostNet, an infamous state-sponsored threat group that some experts connected to China. A third malware known as 9002 RAT, was first observed in 2009 and was used in attacks against South Korean enterprises in 2018. It is reported that the group was conducting cyberespionage attacks against government agencies as well as energy and aerospace companies in Russia, Georgia, and Mongolia.[emaillocker id="1283"]
References:
The following reports contain further technical details: