Ethical Hacking News Hubb
Advertisement Banner
  • Home
  • News
  • Ethical Hackers
  • Contact
No Result
View All Result
  • Home
  • News
  • Ethical Hackers
  • Contact
No Result
View All Result
Wellnessnewshubb
No Result
View All Result
Home Ethical Hackers

New Remote Access Trojan Emerges via Telegram and Discord

admin by admin
August 15, 2023
in Ethical Hackers


Aug 14, 2023THNCyber Threat / Malware

A new remote access trojan (RAT) called QwixxRAT is being advertised for sale by its threat actor through Telegram and Discord platforms.

“Once installed on the victim’s Windows platform machines, the RAT stealthily collects sensitive data, which is then sent to the attacker’s Telegram bot, providing them with unauthorized access to the victim’s sensitive information,” Uptycs said in a new report published today.

The cybersecurity company, which discovered the malware earlier this month, said it’s “meticulously designed” to harvest web browser histories, bookmarks, cookies, credit card information, keystrokes, screenshots, files matching certain extensions, and data from apps like Steam and Telegram.

The tool is offered for 150 rubles for weekly access and 500 rubles for a lifetime license. It also comes in a limited free version.

Cybersecurity

A C#-based binary, QwixxRAT comes with various anti-analysis features to remain covert and evade detection. This includes a sleep function to introduce a delay in the execution process as well as run checks to determine whether it’s operating within a sandbox or virtual environment.

Other functions allow it to monitor for a specific list of processes (e.g., “taskmgr,” “processhacker,” “netstat,” “netmon,” “tcpview,” and “wireshark”), and if detected, halts its own activity until the process is terminated.

QwixxRAT Trojan

Also incorporated in QwixxRAT is a clipper that stealthily accesses sensitive information copied to the device’s clipboard with an aim to conduct illicit fund transfers from cryptocurrency wallets.

Command-and-control (C2) is facilitated by means of a Telegram bot, through which commands are sent to carry out additional data collection such as audio and webcam recordings and even remotely shutdown or restart the infected host.

The disclosure comes weeks after Cyberint disclosed details of two other RAT strains dubbed RevolutionRAT and Venom Control RAT that’s also advertised on various Telegram channels with data exfiltration and C2 connectivity features.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

What Is the New NIST Control for Public Disclosure Programs?

Next Post

ExpressVPN not working with YouTube TV? Try this!

Next Post

ExpressVPN not working with YouTube TV? Try this!

Recommended

Surfshark VPNクーポン:2年間プランで83%OFF

12 months ago

A Gateway to Espionage and Ransomware Operations

4 weeks ago

© Ethical Hacking News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Ethical Hackers
  • Contact

Newsletter Sign Up.

No Result
View All Result
  • Home
  • News
  • Ethical Hackers
  • Contact

© 2022 Ethical Hacking News Hubb All rights reserved.