Cyber Security

Indian Patchwork APT infects itself with Remote Access Trojan

0

An India-linked threat group, tracked as Patchwork employed a new variant of the BADNEWS backdoor, dubbed Ragnatela in a recent campaign. However, the group’s inner workings have been exposed after it accidentally infected its own infrastructure with a remote access Trojan (RAT).

The APT dubbed Patchwork by Malwarebytes which are also tracked under names including Hangover Group, Dropping Elephant, Chinastrats, and Monsoon, has been active since at least 2015. They have launched campaigns designed to deploy RATs for the purposes of data theft and other malicious activities.

In one of the latest attack waves, the group targeted individual faculty members from research institutions specializing in biomedical and molecular sciences.

On January 7, the Malwarebytes team managed to dig into the APT group’s activities after Patchwork managed to infect its own systems with its own RAT creation, resulting in captured keystrokes and screenshots of their own computer and virtual machines.

The researchers stated that Patchwork usually depends on spear-phishing attacks, with tailored emails sent to specific targets. These emails aim to drop RTF files containing the BADNEWS RAT, of which a new variant has now been found.

The latest version of this malware, dubbed Ragnatela, was compiled in November 2021. This Trojan could capture screenshots, keylogging, list OS processes and machine files, upload malware, and execute additional payloads.

Ragnatela is stored in malicious RTF files as OLE objects, often crafted to be official communication from Pakistani authorities. An exploit for a known Microsoft Equation Editor vulnerability is used to execute the RAT.

Prominent victims that were successfully infiltrated include Pakistani Government’s Ministry of Defense, the National Defense University of Islamabad, the Faculty of Bio-Sciences (FBS) at UVAS University, the HEJ Research Institute at the University of Karachi, and the molecular medicine department at SHU University as organizations infiltrated by Patchwork.

Patchwork infected its own development machine with Ragnatela, and so the researchers were also able to see them make use of VirtualBox and VMware virtual machines (VMs) to conduct malware testing.

This is the first time the group has been connected to attacks against the biomedical research community.

Image Credits : Pass Revelator Suite

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hackers use BadUSB to target defense firms with ransomware

Previous article

KCodes NetUSB flaw impacts millions of devices

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *