Threat Advisory

Ransomware Group Targets IT Workers with SharpRhino RAT Malware

Threat: Malware
Targeted Region: Global
Threat Actor Region: Russia
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified a new malware variant linked to the ThunderShell malware family. Dubbed SharpRhino, this Remote Access Trojan (RAT) represents an evolution in the tactics of the ransomware group Hunters International. This marks the first known deployment of SharpRhino by the group, which had not exhibited indicators of using such a RAT. SharpRhino, delivered through a typosquatting domain impersonating Angry IP Scanner, establishes persistence, and enables remote access, showcasing an advanced level of adaptability in Ransomware-as-a-Service tactics.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have identified a new malware variant linked to the ThunderShell malware family. Dubbed SharpRhino, this Remote Access Trojan (RAT) represents an evolution in the tactics of the ransomware group Hunters International. This marks the first known deployment of SharpRhino by the group, which had not exhibited indicators of using such a RAT. SharpRhino, delivered through a typosquatting domain impersonating Angry IP Scanner, establishes persistence, and enables remote access, showcasing an advanced level of adaptability in Ransomware-as-a-Service tactics.[emaillocker id="1283"]

 

SharpRhino employs an infection strategy by leveraging a typosquatting domain to distribute a trojanized installer, initially identified as ipscan-3.9.1-setup.exe. This 32-bit Portable Executable (PE) file, which is a Nullsoft installer, includes a password-protected 7z archive that is extracted upon execution. The malware establishes persistence through registry modifications and utilizes a .bat file to execute obfuscated PowerShell scripts, which compile and run C# code dynamically. The C# code within SharpRhino is heavily obfuscated and employs encryption techniques to secure communication with its Command-and-Control (C2) infrastructure. This allows the malware to perform fileless operations and maintain remote access.

The SharpRhino malware represents a notable development in the capabilities of Hunters International, demonstrating their ability to adapt and evolve their tools and techniques. The malware’s design and use of advanced persistence and communication methods underscore the need for enhanced defensive measures against such evolving threats. It highlights the importance of continuous monitoring and prompt response to emerging ransomware threats, as well as the need for robust security practices to mitigate the risks associated with such advanced malware deployments.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
Persistence T1543 Create or Modify System Process
T1547 Boot or Logon Autostart Execution
Privilege Escalation T1134 Access Token Manipulation
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
T1480 Execution Guardrails
Discovery T1135 Network Share Discovery
Command and Control T1071 Application Layer Protocol
T1573 Encrypted Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hunters-international-ransomware-gang-targets-it-workers-with-new-sharprhino-malware/

[/emaillocker]
crossmenu