RomCom RAT found in applications from spoofed Veeam, SolarWinds and KeePass websites

Discussion in 'malware problems & news' started by waking, Nov 8, 2022.

  1. waking

    waking Registered Member

    Joined:
    Jan 25, 2016
    Posts:
    176
    RomCom RAT found in applications from spoofed Veeam,
    SolarWinds and KeePass websites


    Howard Solomon
    November 4, 2022


    https://www.itworldcanada.com/article/romcom-rat-found-in-applications-from-spoofed-veeam-solarwinds-and-keepass-websites/511672?utm_source=Security&utm_medium=enews&utm_campaign=Security&scid=b2344d5a-4609-b432-f662-4e60014e6876

    "The websites of popular business applications from Veeam,
    SolarWinds, KeePass and PDF Technologies are being spoofed
    by a threat actor to spread the RomCom remote access trojan
    (RAT), according to researchers at BlackBerry and Palo Alto
    Networks."

    ...

    "The threat actor’s campaigns are simple: The creation of
    virtually identical websites for brand name software providers
    that organizations might use, by scraping the companies’ original
    legitimate HTML code. The gang hopes victims will download trial
    versions or pay for the applications. What they download is
    infected software."

    ...

    "The BlackBerry report includes indicators of compromise for
    the RAT."


    The BlackBerry report:

    RomCom Threat Actor Abuses KeePass and SolarWinds
    to Target Ukraine and Potentially the United Kingdom


    11.02.22 / The BlackBerry Research & Intelligence Team

    https://blogs.blackberry.com/en/2022/11/romcom-spoofing-solarwinds-keepass
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Wow scary stuff. But it's not clear to me how these trojanized versions of legitimate tools would work in practice. It seems to me that this RomCom RAT will run as a standalone tool which means that malicious activities should be easier to spot. So it's not trying to hide behind the legitimate tools if I understood correctly.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.