Rewterz Threat Advisory – Multiple Apple iOS and iPadOS Vulnerabilities
August 18, 2022Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
August 18, 2022Rewterz Threat Advisory – Multiple Apple iOS and iPadOS Vulnerabilities
August 18, 2022Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
August 18, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Unauthorized Remote Access
- Keylogging
- Information Theft
- Password Theft
Indicators of Compromise
MD5
- cab2faba54689b8c8fcdab517a233c6e
- bda56b2a058181d5f3534e1616b5e42e
- aeb22b82dd71f498ab254a5cf9ba688d
SHA-256
- 5897432567029362496772c232336e4ad9acf09a9e67a115e2086bffa75cd61e
- 1ba4c9c152ea825c0c037b9786e9379f1836cc9c5b20b8796d5d90a9564d5480
- eb79f8d1aaa370f765a1c17313256341503d0552fc7d3f5fa1895fb0687f35e0
SHA-1
- 9d6e06d8bc174256fc24abf7f4c6ce5c19455614
- d1fb738f2b2d751310504a7cdebfa8d84871ae21
- 3553ab6228d32a5b03fd69e297050c93e7ab6372
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.