Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Stable Near $30,000 But The Bearish Leg Is Far From Over bitcoin news
  • Bitcoin Slips Below $33k As Exchange Inflows Reach Highest Value Since July 2021 bitcoin news
  • Crypto Investors Dump Small Caps For Blue Chips Like Bitcoin bitcoin news
  • Bitcoin Indicator Hits Historical Low Not Seen Since 2015 bitcoin news
  • Iranian Hackers Leveraging BitLocker and DiskCryptor in Ransomware Attacks cyber security news
  • ETH Back Below $2,000, BTC Down 6% to Start the Weekend – Market Updates Bitcoin News bitcoin news
  • Bitcoin Continues To Slide But Displays Bullish Divergences On Charts bitcoin news
  • XMR and SOL Higher on Monday – Market Updates Bitcoin News bitcoin news

Researchers Warn of Nerbian RAT Targeting Entities in Italy, Spain, and the U.K

Posted on May 11, 2022 By root


Nerbian RAT

A previously undocumented remote access trojan (RAT) written in the Go programming language has been spotted disproportionately targeting entities in Italy, Spain, and the U.K.

Called Nerbian RAT by enterprise security firm Proofpoint, the novel malware leverages COVID-19-themed lures to propagate as part of a low volume email-borne phishing campaign that started on April 26, 2022.

“The newly identified Nerbian RAT leverages multiple anti-analysis components spread across several stages, including multiple open-source libraries,” Proofpoint researchers said in a report shared with The Hacker News.

“It is written in operating system (OS) agnostic Go programming language, compiled for 64-bit systems, and leverages several encryption routines to further evade network analysis.”

The messages, amounting to less than 100 in number, purport to be from the World Health Organization about safety measures related to COVID-19, urging potential victims to open a macro-laced Microsoft Word document to access the “latest health advice.”

Nerbian RAT

Enabling the macros displays COVID-19 guidance, including steps for self-isolation, while in the background, the embedded macro triggers an infection chain that delivers a payload called “UpdateUAV.exe”, which acts as dropper for Nerbian RAT (“MoUsoCore.exe”) from a remote server.

The dropper also makes use of the open-source Chacal “anti-VM framework” to make reverse engineering difficult, using it to carry out anti-reversing checks and terminating itself should it encounter any debuggers or memory analysis programs.

Nerbian RAT

The remote access trojan, for its part, is equipped to log keystrokes, capture screenshots, and execute arbitrary commands, before exfiltrating the results back to the server.

While both the dropper and the RAT are said to have been developed by the same author, the identity of the threat actor remains unknown as yet.

Furthermore, Proofpoint cautioned that the dropper could be customized to deliver different payloads in future attacks, although in its current form, it can only retrieve the Nerbian RAT.

“Malware authors continue to operate at the intersection of open-source capability and criminal opportunity,” Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, said in a statement.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Mexican Crypto Exchange Bitso Launches Stable Yield Program – Exchanges Bitcoin News
Next Post: LUNA, UST Move Closer to Zero, as Do Kwon Asks Holders to ‘Stay Strong’ – Markets and Prices Bitcoin News

Related Posts

  • Cisco Issues Patches for 3 New Flaws Affecting Enterprise NFVIS Software cyber security news
  • Chinese Hackers Caught Stealing Intellectual Property from Multinational Companies cyber security news
  • How to Protect Your Data When Ransomware Strikes cyber security news
  • New Sysrv Botnet Variant Hijacking Windows and Linux with Crypto Miners cyber security news
  • Cybercriminals Using New Malware Loader ‘Bumblebee’ in the Wild cyber security news
  • Conti Ransomware Gang Shut Down After Splitting into Smaller Groups cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • How Ethereum Uniswap Reached A Milestone Of $1T In Trading Volume
  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys

Recent Comments

No comments to show.
  • Shanghai High Court Declares Bitcoin Virtual Asset With Economic Value Protected by Chinese Law – Regulation Bitcoin News bitcoin news
  • ETC Climbs to 1-Week High, as AXS Moves Away From 10-Month Low – Market Updates Bitcoin News bitcoin news
  • Cryptovoxels Is Rebranding to Voxels – Press release Bitcoin News bitcoin news
  • LUNA Loses 50% of Its Value, While XMR and AXS Declines Continue – Market Updates Bitcoin News bitcoin news
  • Cardano (ADA) Could Slide Back To $0.40 bitcoin news
  • Ethereum Bears Aim Big After Recent Breakdown Below $2.5K bitcoin news
  • Experts Say Ethereum Will Grow 100% To Hit $5,783 By Year-End bitcoin news
  • How to Practice Trading Online Using Tools Provided By Binaryoptions․com – Sponsored Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme