Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Snoop Dogg, Clay Nation & Cardano Come Together On The Blockchain bitcoin news
  • LUNA Climbs 1,500% Following Do Kwon Tweets, While AVAX and NEAR Fall on Saturday – Market Updates Bitcoin News bitcoin news
  • CFTC Chairman Confirms Bitcoin, Ether Are Commodities – Regulation Bitcoin News bitcoin news
  • Top 5 Bitcoin Mining Softwares To Look Out For bitcoin news
  • Billionaire Ricardo Salinas Fires Back At Warren Buffett’s Bitcoin Slander bitcoin news
  • HUMAN Protocol Foundation Awards Grant to VeritaTrust to Build on-Chain Rewards for Reviews – Press release Bitcoin News bitcoin news
  • Bitcoin Struggles To Hold $40K While Crypto Track US Stocks bitcoin news
  • Bitcoin Reclaims $30K Territory After Recent Weeks’ Struggle bitcoin news

Experts Sound Alarm on DCRat Backdoor Being Sold on Russian Hacking Forums

Posted on May 9, 2022 By root


DCRat Backdoor

Cybersecurity researchers have shed light on an actively maintained remote access trojan called DCRat (aka DarkCrystal RAT) that’s offered on sale for “dirt cheap” prices, making it accessible to professional cybercriminal groups and novice actors alike.

“Unlike the well-funded, massive Russian threat groups crafting custom malware […], this remote access Trojan (RAT) appears to be the work of a lone actor, offering a surprisingly effective homemade tool for opening backdoors on a budget,” BlackBerry researchers said in a report shared with The Hacker News.

“In fact, this threat actor’s commercial RAT sells at a fraction of the standard price such tools command on Russian underground forums.”

Written in .NET by an individual codenamed “boldenis44” and “crystalcoder,” DCRat is a full-featured backdoor whose functionalities can be further augmented by third-party plugins developed by affiliates using a dedicated integrated development environment (IDE) called DCRat Studio.

It was first released in 2018, with version 3.0 shipping on May 30, 2020, and version 4.0 launching nearly a year later on March 18, 2021.

Prices for the trojan start at 500 RUB ($5) for a two-month license, 2,200 RUB ($21) for a year, and 4,200 RUB ($40) for a lifetime subscription, figures which are further reduced during special promotions.

While a previous analysis by Mandiant in May 2020 traced the RAT’s infrastructure to files.dcrat[.]ru, the malware bundle is currently hosted on a different domain named crystalfiles[.]ru, indicating a shift in response to public disclosure.

DCRat Backdoor

“All DCRat marketing and sales operations are done through the popular Russian hacking forum lolz[.]guru, which also handles some of the DCRat pre-sales queries,” the researchers said.

Also actively used for communications and sharing information about software and plugin updates is a Telegram channel which has about 2,847 subscribers as of writing.

DCRat Backdoor

Messages posted on the channel in recent weeks cover updates to CryptoStealer, TelegramNotifier, and WindowsDefenderExcluder plugins, as well as “cosmetic changes/fixes” to the panel.

“Some Fun features have been moved to the standard plugin,” a translated message shared on April 16 reads. “The weight of the build has slightly decreased. There should be no detects that go specifically to these functions.”

Besides its modular architecture and bespoke plugin framework, DCRat also encompasses an administrator component that’s engineered to stealthily trigger a kill switch, which allows the threat actor to remotely render the tool unusable.

The admin utility, for its part, enables subscribers to sign in to an active command-and-control server, issue commands to infected endpoints, and submit bug reports, among others.

Distribution vectors employed to infect hosts with DCRat include Cobalt Strike Beacons and a traffic direction system (TDS) called Prometheus, a subscription-based crimeware-as-a-service (CaaS) solution used to deliver a variety of payloads.

The implant, in addition to gathering system metadata, supports surveillance, reconnaissance, information theft, and DDoS attack capabilities. It can also capture screenshots, record keystrokes, and steal content from clipboard, Telegram, and web browsers.

“New plugins and minor updates are announced almost every day,” the researchers said. “If the threat is being developed and sustained by just one person, it appears that it’s a project they are working on full-time.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Venezuela Bets on De-Dollarization After Foreign Currency and Crypto Tax Is Applied – Emerging Markets Bitcoin News
Next Post: SHIELDS UP in bite sized chunks

Related Posts

  • NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages cyber security news
  • 7 Key Findings from the 2022 SaaS Security Survey Report cyber security news
  • Android and Chrome Users Can Soon Generate Virtual Credit Cards to Protect Real Ones cyber security news
  • Malicious NPM Packages Target German Companies in Supply Chain Attack cyber security news
  • Malware Analysis: Trickbot cyber security news
  • Microsoft Warns of Web Skimmers Mimicking Google Analytics and Meta Pixel Code cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • How Ethereum Uniswap Reached A Milestone Of $1T In Trading Volume
  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys

Recent Comments

No comments to show.
  • Ukrainian CERT Warns Citizens of a New Wave of Attacks Distributing Jester Malware cyber security news
  • Veteran Investor Bill Miller Remains Bullish on Bitcoin — Confirms He Has a Lot of BTC – Markets and Prices Bitcoin News bitcoin news
  • SHIELDS UP in bite sized chunks cyber security news
  • Cryptocurrencies Unlikely to Help Russia Evade Sanctions – Bitcoin News bitcoin news
  • Bitter APT Hackers Add Bangladesh to Their List of Targets in South Asia cyber security news
  • HUMAN Protocol Foundation Awards Grant to VeritaTrust to Build on-Chain Rewards for Reviews – Press release Bitcoin News bitcoin news
  • U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware cyber security news
  • Get Real, Lagarde — The Underlying Asset ‘Guaranteeing’ Your Euro Scam Coin Is a Gun – Op-Ed Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme