Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • The Hacker News
  • FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services
  • The Hacker News

FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services

[email protected] The Hacker News February 25, 2025
0

Chinese Cloud Services

Various industrial organizations in the Asia-Pacific (APAC) region have been targeted as part of phishing attacks designed to deliver a known malware called FatalRAT.

“The threat was orchestrated by attackers using legitimate Chinese cloud content delivery network (CDN) myqcloud and the Youdao Cloud Notes service as part of their attack infrastructure,” Kaspersky ICS CERT said in a Monday report.

“The attackers employed a sophisticated multi-stage payload delivery framework to ensure evasion of detection.”

The activity has singled out government agencies and industrial organizations, particularly manufacturing, construction, information technology, telecommunications, healthcare, power and energy, and large-scale logistics and transportation, in Taiwan, Malaysia, China, Japan, Thailand, South Korea, Singapore, the Philippines, Vietnam, and Hong Kong.

The lure attachments used in the email messages suggest that the phishing campaign is designed to go after Chinese-speaking individuals.

Cybersecurity

It’s worth noting that FatalRAT campaigns have previously leveraged bogus Google Ads as a distribution vector. In September 2023, Proofpoint documented another email phishing campaign that propagated various malware families such as FatalRAT, Gh0st RAT, Purple Fox, and ValleyRAT.

An interesting aspect of both intrusion sets is that they have primarily targeted Chinese-language speakers and Japanese organizations. Some of these activities have been attributed to a threat actor tracked as Silver Fox APT.

The starting point of the latest attack chain is a phishing email containing a ZIP archive with a Chinese-language filename, which, when launched, launches the first-stage loader that, in turn, makes a request to Youdao Cloud Notes in order to retrieve a DLL file and a FatalRAT configurator.

For its part, the configurator module downloads the contents of another note from note.youdao[.]com so as to access the configuration information. It’s also engineered to open a decoy file in an effort to avoid raising suspicion.

The DLL, on the other hand, is a second-stage loader that’s responsible for downloading and installing the FatalRAT payload from a server (“myqcloud[.]com”) specified in the configuration, while displaying a fake error message about a problem running the application.

An important hallmark of the campaign includes the use of DLL side-loading techniques to advance the multi-stage infection sequence and load the FatalRAT malware.

“The threat actor uses a black and white method where the actor leverages the functionality of legitimate binaries to make the chain of events look like normal activity,” Kaspersky said. “The attackers also used a DLL side-loading technique to hide the persistence of the malware in legitimate process memory.”

“FatalRAT performs 17 checks for an indicator that the malware executes in a virtual machine or sandbox environment. If any of the checks fail, the malware stops executing.”

It also terminates all instances of the rundll32.exe process, and gathers information about the system and the various security solutions installed in it, before awaiting further instructions from a command-and-control (C2) server.

Cybersecurity

FatalRAT is a feature-packed trojan that’s equipped to log keystrokes, corrupt Master Boot Record (MBR), turn on/off screen, search and delete user data in browsers like Google Chrome and Internet Explorer, download additional software like AnyDesk and UltraViewer, perform file operations, and start/stop a proxy, and terminate arbitrary processes.

It’s currently not known who is behind the attacks using FatalRAT, although the tactical and instrumentation overlaps with other campaigns suggest that “they all reflect different series of attacks that are somehow related.” Kaspersky has assessed with medium confidence that a Chinese-speaking threat actor is behind it.

“FatalRAT’s functionality gives an attacker almost unlimited possibilities for developing an attack: spreading over a network, installing remote administration tools, manipulating devices, stealing, and deleting confidential information,” the researchers said.

“The consistent use of services and interfaces in Chinese at various stages of the attack, as well as other indirect evidence, indicates that a Chinese-speaking actor may be involved.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

About The Author

[email protected] The Hacker News

See author's posts

Original post here

Continue Reading

Previous: Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA
Next: GitVenom Malware Steals $456K in Bitcoin Using Fake GitHub Projects to Hijack Wallets

Trending Now

Oops: DanaBot Malware Devs Infected Their Own PCs danabot.png 1

Oops: DanaBot Malware Devs Infected Their Own PCs

May 22, 2025
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks chinese-hackers-attacking.jpg 2

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

May 22, 2025
Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise exploitss.jpg 3

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

May 22, 2025
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks chinese.jpg 4

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

May 22, 2025
Webinar: Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program cyber-program.jpg 5

Webinar: Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program

May 22, 2025
Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host exploit.jpg 6

Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host

May 22, 2025

Related Stories

chinese-hackers-attacking.jpg
  • The Hacker News

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

[email protected] The Hacker News May 22, 2025 0
exploitss.jpg
  • The Hacker News

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

[email protected] The Hacker News May 22, 2025 0
chinese.jpg
  • The Hacker News

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

[email protected] The Hacker News May 22, 2025 0
cyber-program.jpg
  • The Hacker News

Webinar: Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program

[email protected] The Hacker News May 22, 2025 0
exploit.jpg
  • The Hacker News

Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host

[email protected] The Hacker News May 22, 2025 0
main.jpg
  • The Hacker News

Identity Security Has an Automation Problem—And It’s Bigger Than You Think

[email protected] The Hacker News May 22, 2025 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Oops: DanaBot Malware Devs Infected Their Own PCs danabot.png 1
  • Krebs On Security

Oops: DanaBot Malware Devs Infected Their Own PCs

May 22, 2025
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks chinese-hackers-attacking.jpg 2
  • The Hacker News

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

May 22, 2025
Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise exploitss.jpg 3
  • The Hacker News

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

May 22, 2025
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks chinese.jpg 4
  • The Hacker News

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

May 22, 2025
Webinar: Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program cyber-program.jpg 5
  • The Hacker News

Webinar: Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program

May 22, 2025
Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host exploit.jpg 6
  • The Hacker News

Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host

May 22, 2025
Identity Security Has an Automation Problem—And It’s Bigger Than You Think main.jpg 7
  • The Hacker News

Identity Security Has an Automation Problem—And It’s Bigger Than You Think

May 22, 2025

You may have missed

danabot.png
  • Krebs On Security

Oops: DanaBot Malware Devs Infected Their Own PCs

BrianKrebs May 22, 2025 0
chinese-hackers-attacking.jpg
  • The Hacker News

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

[email protected] The Hacker News May 22, 2025 0
exploitss.jpg
  • The Hacker News

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

[email protected] The Hacker News May 22, 2025 0
chinese.jpg
  • The Hacker News

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

[email protected] The Hacker News May 22, 2025 0
Copyright © 2025 All rights reserved. | MoreNews by AF themes.