Threat Advisory

Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

An attack targeting Windows users through a trojan downloader called “Trojan.Fruity.1”. This modular downloader allows threat actors to infect computers with various types of malware, depending on their objectives. To increase the attack's success rate and evade detection, the attackers employ several tricks, including multi-stage infection processes, using harmless apps as decoys, and attempting to bypass antivirus protection.[/subscribe_to_unlock_form]

Summary:

An attack targeting Windows users through a trojan downloader called “Trojan.Fruity.1”. This modular downloader allows threat actors to infect computers with various types of malware, depending on their objectives. To increase the attack's success rate and evade detection, the attackers employ several tricks, including multi-stage infection processes, using harmless apps as decoys, and attempting to bypass antivirus protection.[emaillocker id="1283"]

The attack involves a deceptive scheme where malicious websites and specially crafted software installers are used to distribute the trojan. When unsuspecting victims download an app from a fake site, they are redirected to the MEGA file hosting service webpage, which offers a zip file containing the trojan installer package. Upon launching the installer, the user unwittingly installs both the desired harmless program and the Trojan.Fruity.1 components. The multi-stage infection process of the trojan involves using legitimate programs as its "modules". For instance, in one case, Trojan.Fruity.1 was implanted into a Python programming-language library and launched with a valid digital certificate. Once all components are extracted from the installer, the trojan proceeds through several stages, attempting to inject itself into legitimate processes, perform anti-virus evasion, and finally distribute the Remcos RAT spyware trojan.

In response to this threat, users are advised to download software only from trusted sources and utilize reputable antivirus products to detect and remove Trojan.Fruity.1 and its malicious components effectively.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/07/fruity-trojan-uses-deceptive-software.html

[/emaillocker]
crossmenu