Threat Advisory

SloppyRAT Malware Gains Remote Access Through Built-in PowerShell Commands

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

SloppyRAT is a malware family that is likely used in ransomware attacks to establish a foothold for lateral movement. It was distributed through a multi-stage ClickFix infection chain and supports various features, including PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution, and multiple anti-analysis techniques. The malware author included numerous software flaws in the codebase, suggesting that it is still under development. SloppyRAT uses a ClickFix style lure to download and execute a batch script from a domain like finger.linked4x[.]com.

The downloaded batch script copies a malicious executable to the AppData directory using a filename with numbers and extension, which is then used to download IronPython from GitHub. IronPython is renamed and executed to run zlib compressed Base64-encoded Python code via command line, leading to the deployment of CastleLoader and ultimately CastleRAT. SloppyRAT employs several anti-analysis techniques, including string obfuscation, encrypted code blocks, junk code, indirect system calls, and API hashing.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

SloppyRAT is a malware family that is likely used in ransomware attacks to establish a foothold for lateral movement. It was distributed through a multi-stage ClickFix infection chain and supports various features, including PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution, and multiple anti-analysis techniques. The malware author included numerous software flaws in the codebase, suggesting that it is still under development. SloppyRAT uses a ClickFix style lure to download and execute a batch script from a domain like finger.linked4x[.]com.

The downloaded batch script copies a malicious executable to the AppData directory using a filename with numbers and extension, which is then used to download IronPython from GitHub. IronPython is renamed and executed to run zlib compressed Base64-encoded Python code via command line, leading to the deployment of CastleLoader and ultimately CastleRAT. SloppyRAT employs several anti-analysis techniques, including string obfuscation, encrypted code blocks, junk code, indirect system calls, and API hashing.[emaillocker id="1283"]

SloppyRAT's capabilities are sufficient to support information gathering, reconnaissance, and lateral movement for ransomware-related attacks. However, the malware author included extraneous functionality, unusual design choices, and chaotic code. Organizations should take measures to ensure they have proper security solutions in place to detect and prevent ClickFix-style attacks and subsequent payloads.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1027 Obfuscated Files or Information -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Execution E1204 User Execution
Command & Control E1105 Ingress Tool Transfer

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu