banner



Threat actor Patchwork accidentally attacked itself with a RAT

Patchwork, a threat actor based in India, accidentally infected itself with a Remote Assistants Trojan (RAT). The ironic incident was discovered by Malwarebytes, which took the opportunity to proceeds insight equally to how Patchwork utilizes RTF files to spread the BADNEWS (Ragnatela) RAT.

"Ironically, all the information we gathered was possible thanks to the threat actor infecting themselves with their ain RAT, resulting in captured keystrokes and screenshots of their own computer and virtual machines," explained Malwarebytes.

As part of a recent assail, Patchwork spread malicious files by impersonating Pakistani authorities. Documents were sent out every bit attachments that appeared to be legitimate and important. Instead, the files independent an exploit that can compromise a reckoner so execute the RAT.

The following organizations were successfully compromised by the efforts of Patchwork, according to Malwarebytes:

  • Ministry building of Defense- Government of Pakistan
  • National Defense University of Islam Abad
  • Faculty of Bio-Science, UVAS University, Lahore, Pakistan
  • International center for chemic and biological sciences
  • HEJ Research institute of chemistry, International eye for chemical and biological sciences, univeristy of Karachi
  • SHU Academy, Molecular medicine

Patchwork also infected itself with the RAT, which gave Malwarebytes access to quite a bit of information. Malwarebytes was able to encounter that Patchwork uses VirtualBox and VMWare for development. The security firm as well determined that Patchwork uses VPN Secure and CyberGhost to mask its IP accost.

Comedically, Malwarebytes was also able to make up one's mind the local weather of Patchwork's machines. "Other information that can be obtained is that the weather at the fourth dimension was cloudy with 19 degrees and that they haven't updated their Java yet."

Malwarebytes notes that Patchwork is not as sophisticated every bit similar attackers in Russia and North korea.

Source: https://www.windowscentral.com/threat-actor-accidentally-infects-itself-its-own-remote-administration-trojan

Posted by: rawlsupocand.blogspot.com

0 Response to "Threat actor Patchwork accidentally attacked itself with a RAT"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel