BIOPASS RAT: New Malware Sniffs Victims via Live Streaming

BIOPASS RAT
Share It On:

15th July 2021, Kathmandu

We know that we found the latest malware and our aim is to target online gambling companies in China it is related to a watering hole attack, when the visitors are trick then they are started to download a malware loader disguised as a legitimate installer for well-known apps like Adobe Flash Player,  Microsoft Silverlight.

Near examination of the loader display that and it loads either a previously undocumented which is written in python or a Cobalt Strike shellcode backdoor, the latest kind of malware which we get and that’s name is  BIOPASS RAT (remote access trojan).

We know in the BIOPASS RAT they have main features which are found in other malware, like file system assessment, remote desktop access, file exfiltration, and shell command execution.

It also has the ability to deal with the personal information of its victims by stealing web browser and instant messaging client data.

The BIOPASS RAT is especially interesting because it can sniff its victim’s screen by abusing the framework of Open Broadcaster Software(OBS) Studio, a video recording app and favorite or well-liked live streaming, to establish live streaming in a cloud service via Real-Time Messaging Protocol (RTMP).

In addition, the attack misuses the object storage service (OSS) of Alibaba Cloud(Aliyun) to host the BIOPASS RAT Python scripts as well as to keep and store the exfiltrated data from victims.

BIOPASS RAT is still being actively developed. Some example, just a Few markers that we discovered in the analysis time refer to different versions of RAT code, such as “V2” or “BPSV3”.

There are a lot of the loaders that we found and they were used to load Cobalt Strike shellcode by default instead of the BIOPASS RAT malware.

Furthermore, BIOPASS RAT also makes a timetable for tasks it is easy to load the Cobalt Strike shellcode during the initialization, indicating that the malicious actor behind the attack still stiffly relies on Cobalt Strike.

We also found many clues that display how the malware might be added with the Winnti Group(also known as APT41).


Share It On:

Recent Posts

‘Ncell Woman ICON ICT Award 2024’ presented to Bandana Sharma

‘Ncell Woman ICON ICT Award 2024’ presented to Bandana Sharma

Share It On:26th December 2024, Kathmandu This year’s ‘Ncell Woman ICON ICT Award’ has been conferred on Bandana Sharma, recognizing

456 MW Nepal’s Upper Tamakoshi Resumes Power Generation After Landslide Damage

456 MW Nepal’s Upper Tamakoshi Resumes Power Generation After Landslide

Share It On:25th December 2024, Kathmandu The Upper Tamakoshi Hydroelectric Plant, Nepal’s largest with a 456-megawatt capacity, has resumed partial

Bajaj Platina Mileage Champion 2024: Dhangadhi Event Winners, Performance Highlights, and Fuel Efficiency Showcase

Bajaj Platina Mileage Champion 2024: Dhangadhi Event Winners, Performance Highlights,

Share It On: 25th December 2024, Kathmandu The ‘Bajaj Mileage Champion’ event took place in Dhangadhi, Kailali, where local riders

inDrive Partners with ICT Award 2024, Supports Innovation in Nepal’s Startup Ecosystem

inDrive Partners with ICT Award 2024, Supports Innovation in Nepal’s

Share It On:25th December 2024, kathmandu inDrive a global mobility and urban services platform, is proud to announce the winner of

Citizens Bank Easy Dental Partnership: Exclusive Discounts for Customers

Citizens Bank Easy Dental Partnership: Exclusive Discounts for Customers

Share It On: 25th December 2024, Kathmandu Citizens Bank International Ltd. has entered into a partnership with Easy Dental Pvt.

Bajaj Motorcycle Finance Fair 2024 in Nepal: Low Interest Rates & Easy Loan Approval

Bajaj Motorcycle Finance Fair 2024 in Nepal: Low Interest Rates

Share It On:25th December 2024, Kathmandu Hansraj Hulaschand & Company Pvt. Ltd., the official dealer of Bajaj Motorcycles in Nepal,