A newly discovered malware campaign, dubbed Horns&Hooves by Kaspersky, has been targeting private users, retailers, and service businesses primarily in Russia. This campaign has infected over 1,000 victims since its inception in March 2023, leveraging trojans like NetSupport RAT and BurnsRAT to install stealer malware such as Rhadamanthys and Meduza.
How the Attack Works
Initial Vector: Phishing Emails
The campaign begins with phishing emails containing ZIP attachments disguised as requests or bids from potential customers or partners. These archives include:
- JScript scripts masquerading as legitimate files.
- In some cases, additional documents mimicking organizational content to enhance credibility.
Payload Delivery
The phishing attack employs multiple strategies for payload deployment, including:
- HTML Application (HTA) Files
- HTA files download a decoy PNG image using the curl utility.
- Simultaneously, they retrieve and execute malicious scripts using BITSAdmin.
- Subsequent Payloads
- NetSupport RAT: Establishes communication with the attackers' command-and-control (C2) server.
- BurnsRAT: Dropped via an NSIS installer or integrated within JavaScript code.
- Variants and Evolving Tactics
- Mid-May 2023: Use of JavaScript mimicking legitimate libraries like Next.js.
- Late May-June 2023: Integration of malware directly into JavaScript, reworked BAT files for installation.
Key Malware Components
NetSupport RAT
A remote access tool that provides the attackers with the ability to:
- Transfer files.
- Execute commands via Windows CLI.
- Interact with the victim’s desktop.
BurnsRAT
Primarily focuses on establishing Remote Manipulator System (RMS) as a service, enabling attackers to:
- Execute remote commands.
- Manage systems located in different geographic locations.
Stealer Malware
Victims are further exposed to data theft through secondary payloads like Rhadamanthys and Meduza, which harvest sensitive information.
Attribution to TA569
The campaign has been linked to TA569 (aka Gold Prelude, Mustard Tempest, and Purple Vallhund), a known threat actor responsible for operating SocGholish (FakeUpdates) malware.
- Overlaps in tools and configurations used for NetSupport RAT strengthen this connection.
- TA569 is also known to act as an initial access broker, facilitating ransomware operations such as WastedLocker.
Potential Consequences
The outcomes of this campaign can range from:
- Data theft and system compromise.
- Ransomware deployment resulting in encrypted and damaged systems.
- Installation of additional malware, such as credential stealers.
Mitigation and Prevention
- Educate Employees
Train users to recognize phishing emails and suspicious file attachments. - Secure Email Gateways
Deploy email filtering solutions to block malicious attachments. - Patch Known Vulnerabilities
Regularly update software to mitigate exploitation risks. - Monitor Network Activity
Use tools to detect unusual outbound connections to C2 servers. - Endpoint Protection
Implement advanced threat detection and response tools.
The Horns&Hooves campaign highlights the ever-evolving tactics of cybercriminals targeting unsuspecting victims. By exploiting phishing techniques and leveraging versatile malware like NetSupport RAT and BurnsRAT, attackers continue to pose significant threats. Proactive security measures are crucial to defend against such sophisticated campaigns.