Threat Advisory

Neptune RAT Leverages PowerShell for Silent Payload Execution

Threat: Malware
Threat Actor Name: Freemasonry group
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A new version of Neptune RAT, a highly dangerous remote access trojan, has been discovered circulating on platforms like GitHub, Telegram, and YouTube. Marketed as the "Most Advanced RAT," this malware targets Windows users and employs sophisticated techniques to evade detection. The malware is distributed using PowerShell commands (irm and iex) to download and execute malicious scripts hosted on file-sharing services like catbox.moe. Once executed, Neptune RAT drops into the victim’s AppData folder and establishes a connection with the attacker’s server. The malware is packed with multiple harmful features, including ransomware, credential theft, live desktop monitoring, and anti-analysis mechanisms. Despite claims of being for educational purposes, its capabilities and distribution methods suggest malicious intent. The developer has obfuscated the code using Arabic characters and custom encryption, making analysis difficult. Additionally, the malware employs persistence techniques such as registry modifications and Task Scheduler entries to maintain long-term access.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A new version of Neptune RAT, a highly dangerous remote access trojan, has been discovered circulating on platforms like GitHub, Telegram, and YouTube. Marketed as the "Most Advanced RAT," this malware targets Windows users and employs sophisticated techniques to evade detection. The malware is distributed using PowerShell commands (irm and iex) to download and execute malicious scripts hosted on file-sharing services like catbox.moe. Once executed, Neptune RAT drops into the victim’s AppData folder and establishes a connection with the attacker’s server. The malware is packed with multiple harmful features, including ransomware, credential theft, live desktop monitoring, and anti-analysis mechanisms. Despite claims of being for educational purposes, its capabilities and distribution methods suggest malicious intent. The developer has obfuscated the code using Arabic characters and custom encryption, making analysis difficult. Additionally, the malware employs persistence techniques such as registry modifications and Task Scheduler entries to maintain long-term access.[emaillocker id="1283"]

Neptune RAT is written in Visual Basic .NET and heavily obfuscated, with high entropy levels indicating packing or encryption. It uses custom heaps to store sensitive strings, including decryption keys and Arabic text, further complicating reverse engineering. The malware communicates over TCP, generating unique IDs for each infected device and supporting up to 500 simultaneous connections. It gathers extensive system information, including hardware details, security settings, and installed applications. Modular DLLs enable various malicious functions, such as ransomware (encrypting files with a .ENC extension), UAC bypass, and password theft from browsers like Chrome and Brave. A crypto clipper monitors the clipboard for cryptocurrency addresses and replaces them with the attacker’s wallet. The malware also includes destructive capabilities, such as corrupting the Master Boot Record (MBR) and deleting registry hives, which can render the system unusable. Anti-VM checks terminate execution if a virtual environment is detected, hindering analysis. Persistence is achieved through registry run keys and scheduled tasks, ensuring the malware survives reboots. The builder allows attackers to customize features like anti-detection and USB spreading, while the final payload is delivered via encoded PowerShell scripts.

Neptune RAT represents a significant threat due to its advanced evasion techniques, multi-functional payload, and persistent control over infected systems. Its ability to steal credentials, manipulate financial transactions, and destroy data makes it particularly dangerous. The use of legitimate platforms like GitHub and catbox.moe for distribution complicates detection, while obfuscation methods slow down analysis. The malware’s modular design allows attackers to deploy additional payloads dynamically, increasing its potential impact. With capabilities ranging from ransomware to real-time surveillance, Neptune RAT poses a severe risk to both individuals and organizations. Continuous monitoring and advanced threat detection are essential to counter this evolving threat. The malware’s development and distribution indicate active efforts by cybercriminals to refine their tools, making it critical to stay vigilant against such attacks.

THREAT PROFILE:

Tactic Technique ID Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
Persistence T1547 Boot or Logon Autostart Execution
Privilege Escalation T1548 Abuse Elevation Control Mechanism
Defense Evasion T1027 Obfuscated Files or Information
Credential Access T1555 Credentials from Password Stores
T1606 Forge Web Credentials
T1056 Input Capture
Discovery T1087 Account Discovery
T1217 Browser Information Discovery
T1083 File and Directory Discovery
T1082 System Information Discovery
Collection T1123 Audio Capture
T1185 Browser Session Hijacking
T1115 Clipboard Data
T1005 Data from Local System
T1113 Screen Capture
T1125 Video Capture
Command and Control T1572 Protocol Tunneling
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1491 Defacement
T1565 Data Manipulation

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu