Summary:
Researchers found that hackers are actively exploiting known vulnerabilities in remote desktop software to deploy the PlugX malware. The PlugX malware is a remote access trojan (RAT) that allows hackers to gain remote access to infected systems. Once installed, it can steal sensitive information, take screenshots, and execute remote commands on the infected system. PlugX uses DLL side-loading technique for installing a malicious DLL alongside a legitimate program in the same path, then exploiting the legitimate software's execution to load the malicious DLL, which then launches the malicious function.[/subscribe_to_unlock_form]
Summary:
Researchers found that hackers are actively exploiting known vulnerabilities in remote desktop software to deploy the PlugX malware. The PlugX malware is a remote access trojan (RAT) that allows hackers to gain remote access to infected systems. Once installed, it can steal sensitive information, take screenshots, and execute remote commands on the infected system. PlugX uses DLL side-loading technique for installing a malicious DLL alongside a legitimate program in the same path, then exploiting the legitimate software's execution to load the malicious DLL, which then launches the malicious function.[emaillocker id="1283"]
Attacks against systems that either have unpatched vulnerabilities or have settings that are not appropriate are being observed by researchers. Subsequently, the researcher confirmed that remote-control programs exploiting the RCE vulnerability are being used to install PlugX malware. The researcher verified that a file called esetservice.exe is created by the PowerShell command run as a result of this vulnerability exploitation. A researcher found that in addition to downloading esetservice.exe, the threat actor also downloaded a file with the name http dll.dll. The "esetservice.exe" program contains a function that loads the "http dll.dll" file in the same directory. And This standard DLL side-loading approach is used by PlugX malware.
PlugX is one of the main backdoor malware used by APT threat groups based in China. New features are being added to it even to this day as it continues to see steady use in attacks. Therefore, users must update their installed software to the latest version to pre-emptively prevent vulnerability exploitations.
Threat Profile:
| Tactics | Technique Id | Technique |
| Execution | T1047 | Windows Management Instrumentation |
| T1059 | Command and Scripting Interpreter | |
| T1129 | Shared Modules | |
| T1569 | System Services | |
| Persistence | T1574 | Hijack Execution Flow |
| Privilege Escalation | T1055 | Process Injection |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| T1055 | Process Injection | |
| Credential Access | T1056 | Input Capture |
| Discovery | T1018 | Remote System Discovery |
| Collection | T1056 | Input Capture |
| Command and Control | T1071 | Application Layer Protocol |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/03/hackers-exploiting-remote-desktop.html
[/emaillocker]