Threat Advisory

Remcos RAT Exploits Adult Games in Latest Wave of Malicious Distribution

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A recent report from researchers highlights a concerning trend in South Korea where the Remcos Remote Access Trojan (RAT) malware is being distributed disguised as adult games through webhards, commonly used platforms for malware distribution in the region. The attackers are employing well-known tactics of disguising malware as seemingly legitimate programs, such as games or adult content, to deceive users. This isn't the first instance, as the researcher has previously reported on the distribution of malware like njRAT and UDP RAT through similar means.[/subscribe_to_unlock_form]

Summary:

A recent report from researchers highlights a concerning trend in South Korea where the Remcos Remote Access Trojan (RAT) malware is being distributed disguised as adult games through webhards, commonly used platforms for malware distribution in the region. The attackers are employing well-known tactics of disguising malware as seemingly legitimate programs, such as games or adult content, to deceive users. This isn't the first instance, as the researcher has previously reported on the distribution of malware like njRAT and UDP RAT through similar means.[emaillocker id="1283"]

The attackers are using a variety of tactics to distribute the Remcos RAT malware. Malicious files are disguised as game launchers, with the actual malicious components stored separately. Users are instructed to run a Game.exe file, which, when decompressed, reveals the actual malware. The malware includes VBS scripts that execute alongside the game file. The infection flow involves the execution of ffmpeg.exe, which extracts an encrypted binary and Key value from a file named test.jpg. These are then injected into explorer.exe, initiating the download of Remcos RAT through a command and control (C&C) server. The malware further attempts to perform additional malicious behaviors by injecting into ServiceModelReg.exe.

This report underscores the ongoing threat of malware distribution through file-sharing websites, particularly in South Korea. Users are advised to exercise caution when downloading and running executables from such platforms. The attackers' use of disguises, such as adult games, highlights the need for heightened awareness and security measures. Ultimately, the ASEC recommends users download programs only from official websites to mitigate the risk of falling victim to these increasingly sophisticated and deceptive malware distribution tactics.

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2024/01/remcos-rat-spreading-through-adult.html

[/emaillocker]
crossmenu