Hacking

Horns&Hooves Campaign Targets Russian Entities with NetSupport RAT and BurnsRAT

Published  ·  3 min read

A newly discovered malware campaign, dubbed Horns&Hooves by Kaspersky, has been targeting private users, retailers, and service businesses primarily in Russia. This campaign has infected over 1,000 victims since its inception in March 2023, leveraging trojans like NetSupport RAT and BurnsRAT to install stealer malware such as Rhadamanthys and Meduza.

How the Attack Works

Initial Vector: Phishing Emails

The campaign begins with phishing emails containing ZIP attachments disguised as requests or bids from potential customers or partners. These archives include:

  1. JScript scripts masquerading as legitimate files.
  2. In some cases, additional documents mimicking organizational content to enhance credibility.

Payload Delivery

The phishing attack employs multiple strategies for payload deployment, including:

  1. HTML Application (HTA) Files
    1. HTA files download a decoy PNG image using the curl utility.
    2. Simultaneously, they retrieve and execute malicious scripts using BITSAdmin.
  1. Subsequent Payloads
    1. NetSupport RAT: Establishes communication with the attackers' command-and-control (C2) server.
    2. BurnsRAT: Dropped via an NSIS installer or integrated within JavaScript code.
  1. Variants and Evolving Tactics
    1. Mid-May 2023: Use of JavaScript mimicking legitimate libraries like Next.js.
    2. Late May-June 2023: Integration of malware directly into JavaScript, reworked BAT files for installation.

Key Malware Components

NetSupport RAT

A remote access tool that provides the attackers with the ability to:

  1. Transfer files.
  2. Execute commands via Windows CLI.
  3. Interact with the victim’s desktop.

BurnsRAT

Primarily focuses on establishing Remote Manipulator System (RMS) as a service, enabling attackers to:

  1. Execute remote commands.
  2. Manage systems located in different geographic locations.

Stealer Malware

Victims are further exposed to data theft through secondary payloads like Rhadamanthys and Meduza, which harvest sensitive information.

Attribution to TA569

The campaign has been linked to TA569 (aka Gold Prelude, Mustard Tempest, and Purple Vallhund), a known threat actor responsible for operating SocGholish (FakeUpdates) malware.

  1. Overlaps in tools and configurations used for NetSupport RAT strengthen this connection.
  2. TA569 is also known to act as an initial access broker, facilitating ransomware operations such as WastedLocker.

Potential Consequences

The outcomes of this campaign can range from:

  1. Data theft and system compromise.
  2. Ransomware deployment resulting in encrypted and damaged systems.
  3. Installation of additional malware, such as credential stealers.

Mitigation and Prevention

  1. Educate Employees
    Train users to recognize phishing emails and suspicious file attachments.
  2. Secure Email Gateways
    Deploy email filtering solutions to block malicious attachments.
  3. Patch Known Vulnerabilities
    Regularly update software to mitigate exploitation risks.
  4. Monitor Network Activity
    Use tools to detect unusual outbound connections to C2 servers.
  5. Endpoint Protection
    Implement advanced threat detection and response tools.

The Horns&Hooves campaign highlights the ever-evolving tactics of cybercriminals targeting unsuspecting victims. By exploiting phishing techniques and leveraging versatile malware like NetSupport RAT and BurnsRAT, attackers continue to pose significant threats. Proactive security measures are crucial to defend against such sophisticated campaigns.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067