SafeBreach researchers have documented a sophisticated remote access trojan called CodeRAT – aimed at Farsi-speaking software developers to steal data.
This RAT is said to be capable of performing around 50 operations – from reconnaissance to stealing data in various instances. And with researchers approaching the CodeRAT author talking about his activities, he decided to publish his malware source code open on GitHub.
CodeRAT Source Code
Remote access trojans are so popular for their reconnaissance and data-stealing capabilities. But they follow a regular process or infrastructure that often leaks their modus operandi and makes them not interesting.
But here’s one called CodeRAT – a sophisticated remote access trojan that uses a Telegram bot for functioning as asked and an anonymous public file uploading API for exporting the stolen data. Aimed at Farsi-speaking software developers, the threat actor here starts the campaign by sending a Word document laced with Microsoft Dynamic Data Exchange (DDE) exploit in it.
Unpacking and running this exploit will bring the CodeRAT malware from it’s GitHub repository and installs it on the target machine. Then, the hacker can uses any of the below methods to send commands to the CodeRAT residing on the victim’s system;
- Telegram bot API with proxy (no direct requests)
- Manual mode (includes USB option)
- Locally stored commands on the ‘myPictures’ folder
Similarly, he can use these three means to obtain sensitive data too, from the victim’s system. In a unique way, researchers said CodeRAT uses a public anonymous file hosting API for exfiltrating the stolen data instead of a command and control server like we see in regular RAT operations.
It’s further said that CodeRAT can perform around 50 commands like taking screenshots, copying clipboard content, getting a list of running processes, terminating processes, checking GPU usage, downloading, uploading, deleting files, and executing programs.
Though the operation is now halted, the source code of this RAT is now made open-source by the author after he was approached by the researchers questioning him about the attacks linked to CodeRAT. This may now lead to more potential attacks by other hackers who leverage the CodeRAT code.
Other Trending News:- Â News