- Aug 17, 2014
- 11,111
A spear-phishing campaign targeting Indian government entities aims to deploy an updated version of a backdoor called ReverseRAT.
Cybersecurity firm ThreatMon attributed the activity to a threat actor tracked as SideCopy.
"Once ReverseRAT gains persistence, it enumerates the victim's device, collects data, encrypts it using RC4, and sends it to the command-and-control (C2) server," the company said in a report published last week.
"It waits for commands to execute on the target machine, and some of its functions include taking screenshots, downloading and executing files, and uploading files to the C2 server."
Researchers Warn of ReverseRAT Backdoor Targeting Indian Government Agencies
A Pakistani threat group called SideCopy is suspected of being behind the spear-phishing campaign targeting Indian government entities.
thehackernews.com