ReverseRat, a Pakistani Trojan Targeting Indian Entities

AmarchyGrabber Discord Trojan

The cyber warfare between India and Pakistan continues. This time, an unknown Pakistani threat actor has been using a new malware, called ReverseRat, to compromise the network security of India-based power companies. This new threat was often used in combination with other payloads, and it seems that its primary purpose is to data theft and reconnaissance. While ReverseRat's features are not very advanced, it packs more than enough functionality to allow its operators to carry out all sorts of tasks on the systems they compromise.

ReverseRat Employed in Attacks Against Indian Power Companies

So far, researchers have been unable to pinpoint the exact methods that the criminals use to deliver the implant, but it is very likely that they are relying on email attachments. If a user ends up interacting with the shady email, they might be prompted to download a file attachment or a file hosted on an external site. The file in question is typically a ZIP archive, which contains either an LNK or a PDF file. These two files can execute malicious code if the user grants them certain permissions. The topics of these fake documents may vary, but the criminals appear to be focusing on subjects specific to the energy sector, or related to the COVID-19 vaccines.

ReverseRat Packs a Hefty Number of Features

Prior to running, ReverseRat will collect some basic information about the network it has compromised – MAC address, IP address, hardware and software configuration, and the computer name. Once running, it has the ability to perform several tasks:

  • Download and launch executable files.
  • Steal files.
  • Run a new process.
  • Manage the file system.
  • List directory contents.
  • View running process and manage them.
  • Hijack the clipboard.
  • Grab screenshots.

The ReverseRat Trojan packs the ability to execute some of its components in-memory, therefore minimizing the data footprint it leaves on the systems it compromises. However, its attack is not entirely fileless, and this should be easily detectable by reputable antivirus products.

July 6, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.