Summary:
Researchers recently discovered a new threat, the Saw RAT within a ZIP archive file. The ZIP archive included a deceptive shortcut file (.lnk) with an Adobe icon that, when executed, triggered a JavaScript to initiate the execution of a Java-based Remote Access Trojan (RAT). This RAT, named "Saw RAT" by CRIL, demonstrated sophisticated capabilities, such as collecting system information, transferring files, listing directories, executing arbitrary commands, and establishing a socket connection for communication between the server and client.[/subscribe_to_unlock_form]
Summary:
Researchers recently discovered a new threat, the Saw RAT within a ZIP archive file. The ZIP archive included a deceptive shortcut file (.lnk) with an Adobe icon that, when executed, triggered a JavaScript to initiate the execution of a Java-based Remote Access Trojan (RAT). This RAT, named "Saw RAT" by CRIL, demonstrated sophisticated capabilities, such as collecting system information, transferring files, listing directories, executing arbitrary commands, and establishing a socket connection for communication between the server and client.[emaillocker id="1283"]
The ZIP file contained a folder with a deceptive PDF file and a malicious JAR file named "jpackage.jar." The execution process involved copying a zip file, extracting it in the %temp% folder, and triggering the JavaScript file "jp.js." This file, in turn, opened the deceptive PDF file, prompting for a password, and executed the malicious JAR file. The Saw RAT, a Java Archive file, exhibited various functionalities, including connecting to a remote server, sending heartbeat messages, and responding to commands from the Command and Control (C&C) server. The RAT could perform operations such as collecting system information, listing directories, capturing screenshots, and executing arbitrary commands.
Researchers did not observe any activities from the attacker's side due to an inactive C&C server, the potential risks posed by Saw RAT are significant. If the data exfiltration is successful, threat actors could exploit the compromised systems for various malicious activities, such as financial motives, espionage, or disruptive actions. Researchers emphasizes the importance of cybersecurity best practices, including deploying strong email filtering systems, limiting scripting language execution, using robust antivirus solutions, monitoring network activities, strengthening password practices, and staying informed about the latest phishing and social engineering methods. Overall, the analysis underscores the need for vigilance and proactive measures to protect against evolving cyber threats.
Threat Profile:

References:
The following reports contain further technical details:
https://cyble.com/blog/uncovering-the-new-java-based-saw-rats-infiltration-strategy-via-lnk-files/
[/emaillocker]