EternalBlue exploit being employed to deliver RAT Trojan

Discussion in 'malware problems & news' started by hawki, May 21, 2017.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    "Threat actors are using the same EternalBlue exploit employed by WannaCry to deliver other malware—specifically, a remote access trojan (RAT) typically used to spy on people’s activities or take control of their computers...

    The RAT has plenty of spy features, the firm said, including screen and keyboard monitoring, audio and video surveillance, the ability to transfer, download or delete files and data, and general control of the infected machine. It also takes care to block the exploit from being used for other malware...

    'Unlike WannaCry, this threat infects only once and does not spread. It is not a worm.' "

    https://www.infosecurity-magazine.com/news/wannacry-exploit-used-to-spread/
     
  2. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    "RAT Trojan"? Remote Access Trojan Trojan. :argh:
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Makes sense. RATs are always looking for SMB and RDP vulnerabilities to exploit.
     
  4. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Double Trouble :)

    My Bad
     
  5. guest

    guest Guest

    where did you saw that?
     
  6. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Read the title of this thread. ;)
     
  7. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    hawki said: R[emote]A[cess]T[rojan] Trojan.

    krusty is correcting hawki's malware grammar.

    hawki used "to deliver RAT Trojan" to avoid any possible confusion with a James Cagney flick :)

    "...you dirty, double-crossin' Remote Acess Trojan!"
     
    Last edited: May 22, 2017
  8. guest

    guest Guest

    oh ok lol , i thought the author of the article made the mistake :p
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.