App Review Those Nasty RATS Part 2

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
For those looking for a career in Computer Security, understanding how RATs work can be very, very beneficial. Over the past few years many hacking groups will install RATs of varying type on innocent servers, then using these infected Servers as a platform to carry out an attack on the real target. Depending on the skill of the attack Group, the layers of innocent compromised Servers may be 3 or 4 deep in order to hide anyone from following the trail back to the Group, this exposing them. Just as a security application will look for evidence of compromise, so will the malware RAT look for evidence of detection on the initial Server. If such detection is in evidence, the other Server layers (termed Failsafers) can be cut out thus protecting the attackers.

A whole industry is currently under development that concerns itself with things like this, the best known being iSight, Area1 and Shape Security. catering to the Enterprise sector, annual protection contracts frequently exceed 1 million USD annually. Point being that their may be Gold in RATs for the right people.
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
A few things:

1). Fleischmann- The reason I tested Comodo in this way was to lay the foundation for something more elaborate that will be seen in part 5, which will essentially be a video demonstration of data I sent them last December.

2). Kate- this sort of malware, signed and targeted, has in all probability been extent on certain servers for years and is still not detected. And as pointed out in Part 1, the technique is much, much older than 2009; but as long as IT "Pro's" remain ignorant to the threat it should work well into the future to the detriment of us all.

3). LC- The song sounds better in a warm bath with candles and a glass of wine.

4). James- Superb point. I've wanted so many times to smash some people in the head with a bat (not that I would do so, being kind and gentle) in order to wake them up to such threats. How many breaches must occur before there is a realization that traditional methods of security are antiquated?
 

Rishi

Level 19
Verified
Honorary Member
Top Poster
Well-known
Dec 3, 2015
938
Thank you very informative series you have got going, the variety they have(cover a lot C++, Java, Python,VB, Perl) and tricks to avoid the modern AV technologies is just scary. Sandboxing and virtualization excel here.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I assume you had a good reason not to publicize the vendor whose name appears on this abused certificate.
As you mentioned, some security softs use a trusted vendors list.
Would you recommend keeping the trusted vendors list as short as possible, for instance, microsoft + google/mozilla + vendors of necessary hardware drivers?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top