EXECUTIVE SUMMARY
Researchers have identified a new malware variant linked to the ThunderShell malware family. Dubbed SharpRhino, this Remote Access Trojan (RAT) represents an evolution in the tactics of the ransomware group Hunters International. This marks the first known deployment of SharpRhino by the group, which had not exhibited indicators of using such a RAT. SharpRhino, delivered through a typosquatting domain impersonating Angry IP Scanner, establishes persistence, and enables remote access, showcasing an advanced level of adaptability in Ransomware-as-a-Service tactics.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have identified a new malware variant linked to the ThunderShell malware family. Dubbed SharpRhino, this Remote Access Trojan (RAT) represents an evolution in the tactics of the ransomware group Hunters International. This marks the first known deployment of SharpRhino by the group, which had not exhibited indicators of using such a RAT. SharpRhino, delivered through a typosquatting domain impersonating Angry IP Scanner, establishes persistence, and enables remote access, showcasing an advanced level of adaptability in Ransomware-as-a-Service tactics.[emaillocker id="1283"]
SharpRhino employs an infection strategy by leveraging a typosquatting domain to distribute a trojanized installer, initially identified as ipscan-3.9.1-setup.exe. This 32-bit Portable Executable (PE) file, which is a Nullsoft installer, includes a password-protected 7z archive that is extracted upon execution. The malware establishes persistence through registry modifications and utilizes a .bat file to execute obfuscated PowerShell scripts, which compile and run C# code dynamically. The C# code within SharpRhino is heavily obfuscated and employs encryption techniques to secure communication with its Command-and-Control (C2) infrastructure. This allows the malware to perform fileless operations and maintain remote access.
The SharpRhino malware represents a notable development in the capabilities of Hunters International, demonstrating their ability to adapt and evolve their tools and techniques. The malware’s design and use of advanced persistence and communication methods underscore the need for enhanced defensive measures against such evolving threats. It highlights the importance of continuous monitoring and prompt response to emerging ransomware threats, as well as the need for robust security practices to mitigate the risks associated with such advanced malware deployments.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1543 | Create or Modify System Process |
| T1547 | Boot or Logon Autostart Execution | |
| Privilege Escalation | T1134 | Access Token Manipulation |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| T1480 | Execution Guardrails | |
| Discovery | T1135 | Network Share Discovery |
| Command and Control | T1071 | Application Layer Protocol |
| T1573 | Encrypted Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-gang-targets-it-workers-with-new-sharprhino-malware/