Full Report
2025-01-03 • Nimantha Deshappriya • win.asyncrat, win.quasar_rat, win.remcos Open article on Malpedia
Analysis Summary
# Tool/Technique: Win.AsyncRAT
## Overview
Win.AsyncRAT is mentioned as one of the Remote Access Trojans (RATs) observed in the context of Sri Lanka's cybersecurity landscape, suggesting its use as a post-compromise access tool.
## Technical Details
- Type: Malware family (Remote Access Trojan - RAT)
- Platform: Likely Windows (implied by 'win.')
- Capabilities: Provides remote access and control capabilities to an attacker.
- First Seen: Information not specified in the context.
## MITRE ATT&CK Mapping
Based on typical RAT functionality:
- TA0011 - Command and Control
- T1071 - Application Layer Protocol
- TA0003 - Persistence
- T1547 - Boot or Logon Autostart Execution
## Functionality
### Core Capabilities
- Establishing persistent remote connections.
- Executing commands remotely.
### Advanced Features
- Specific advanced features of AsyncRAT are not detailed in the provided context snippet.
## Indicators of Compromise
- File Hashes: N/A
- File Names: N/A
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: N/A
## Associated Threat Actors
- The context suggests observation within the Sri Lankan threat environment, but specific threat actor attribution for the usage of this variant is not provided.
## Detection Methods
- Detection would typically rely on signatures for the file binary, monitoring for outbound connections to known C2 infrastructure, and behavioral analysis indicative of a RAT opening remote desktop or file transfer channels.
- YARA rules: Not available in the context.
## Mitigation Strategies
- Network Segmentation and Firewall rules to restrict unauthorized outbound C2 communication.
- Application whitelisting to prevent execution of unauthorized remote management tools.
- User education regarding phishing/social engineering leading to RAT installation.
## Related Tools/Techniques
- Win.Quasar_RAT (Mentioned alongside it)
- Win.Remcos (Mentioned alongside it)
***
# Tool/Technique: Win.Quasar_RAT
## Overview
Win.Quasar_RAT is listed among the Remote Access Trojans (RATs) observed in the Sri Lankan cybersecurity environment, indicating its use by malicious actors for maintaining remote control over compromised systems.
## Technical Details
- Type: Malware family (Remote Access Trojan - RAT)
- Platform: Likely Windows (implied by 'win.')
- Capabilities: Provides remote access, file management, keylogging, or webcam access (typical RAT functions).
- First Seen: Information not specified in the context.
## MITRE ATT&CK Mapping
Based on typical RAT functionality:
- TA0011 - Command and Control
- T1071 - Application Layer Protocol
- TA0001 - Initial Access
- T1566 - Phishing (if delivered via email)
## Functionality
### Core Capabilities
- Remote execution of system commands.
- Management of target files and processes.
### Advanced Features
- Specific advanced features of Quasar RAT usage are not detailed in the provided context snippet.
## Indicators of Compromise
- File Hashes: N/A
- File Names: N/A
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: N/A
## Associated Threat Actors
- Observed in the Sri Lankan threat landscape, but no specific TAs are named in the context snippet.
## Detection Methods
- Signature matching on known Quasar executables.
- Monitoring for outgoing network traffic characteristic of Quasar C2 channels.
## Mitigation Strategies
- Strong endpoint protection solutions configured to detect RAT execution patterns.
- Monitoring for unauthorized remote desktop sessions or suspicious process injection.
## Related Tools/Techniques
- Win.AsyncRAT (Mentioned alongside it)
- Win.Remcos (Mentioned alongside it)
***
# Tool/Technique: Win.Remcos
## Overview
Win.Remcos is identified as one of the Remote Access Trojans active in the context of analyzed security incidents specific to Sri Lanka.
## Technical Details
- Type: Malware family (Remote Access Trojan - RAT)
- Platform: Likely Windows (implied by 'win.')
- Capabilities: Highly functional RAT often used for data exfiltration and system control.
- First Seen: Information not specified in the context.
## MITRE ATT&CK Mapping
Based on typical RAT functionality:
- TA0002 - Execution
- T1059 - Command and Scripting Interpreter
- TA0010 - Exfiltration
- T1041 - Exfiltration Over C2 Channel
## Functionality
### Core Capabilities
- Comprehensive system control from a remote attacker.
- Potential for keylogging and credential dumping.
### Advanced Features
- Remcos often supports features like password grabbing and file system manipulation.
## Indicators of Compromise
- File Hashes: N/A
- File Names: N/A
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: N/A
## Associated Threat Actors
- No specific threat actor is named in relation to this observation.
## Detection Methods
- Detection often focuses on the binary's known characteristics and its communication protocols.
- Specific behavioral modeling for Remcos's file handling capabilities.
## Mitigation Strategies
- Restricting the execution of downloaded binary files unless verified.
- Implementing least privilege principles to limit the damage a compromised Remcos instance can inflict.
## Related Tools/Techniques
- Win.AsyncRAT (Mentioned alongside it)
- Win.Quasar_RAT (Mentioned alongside it)
***
# Tool/Technique: SideWinder (T-APT-04) Activities
## Overview
SideWinder (also tracked as T-APT-04) is a sophisticated threat actor group that was observed conducting activities related to Sri Lanka in late 2024. This suggests targeted, potentially state-sponsored operations.
## Technical Details
- Type: Threat Actor Group / Advanced Persistent Threat (APT)
- Platform: Multiple, but associated activity pertains to the Sri Lankan context.
- Capabilities: Highly capable; known for espionage and persistent access.
- First Seen: Activities referenced from 2024-10-05.
## MITRE ATT&CK Mapping
(Mappings are generalized for a sophisticated APT group):
- TA0001 - Initial Access
- TA0005 - Lateral Movement
- TA0006 - Credential Access
## Functionality
### Core Capabilities
- Likely utilizing custom or sophisticated C2 infrastructure.
- Targeting specific organizational or governmental entities.
### Advanced Features
- Given the APT designation, highly advanced techniques like custom malware development, anti-analysis measures, and long-term persistence are expected.
## Indicators of Compromise
- File Hashes: N/A (Specific artifacts from the investigation are not listed here)
- File Names: N/A
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: N/A
## Associated Threat Actors
- SideWinder (T-APT-04)
## Detection Methods
- Detection relies heavily on threat intelligence sharing regarding SideWinder infrastructure and custom malware families.
- Hunting for behaviors associated with known SideWinder campaigns.
## Mitigation Strategies
- Implementing robust perimeter defenses capable of deep packet inspection.
- Regular vulnerability management against systems targeted by sophisticated APTs.
- Enhanced monitoring for data staging and low-and-slow exfiltration attempts.
## Related Tools/Techniques
- Custom espionage toolsets associated with APT activity.
- Potential overlap with other operations targeting South Asian entities.
***
# Tool/Technique: Lumma Stealer
## Overview
Lumma Stealer is a publicly available information-stealing malware observed in network traffic analysis from September 2024.
## Technical Details
- Type: Malware family (Infostealer)
- Platform: Not specified, but typically targets Windows.
- Capabilities: Stealing sensitive information such as credentials, cookies, and cryptocurrency wallet data.
- First Seen: Activity referenced from 2024-09-21.
## MITRE ATT&CK Mapping
- TA0010 - Exfiltration
- T1041 - Exfiltration Over C2 Channel
- TA0006 - Credential Access
- T1552 - Unsecured Credentials
## Functionality
### Core Capabilities
- Harvesting credentials from browsers, email clients, and FTP clients.
- Collecting system information and cryptocurrency wallets.
### Advanced Features
- Likely utilizes encrypted communication channels for C2.
- Techniques to ensure persistence post-installation.
## Indicators of Compromise
- File Hashes: N/A
- File Names: N/A
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: Attempts to access sensitive data stores/directories.
## Associated Threat Actors
- General cybercriminal actors who purchase or utilize Malware-as-a-Service (MaaS) offerings for Lumma Stealer.
## Detection Methods
- Monitoring for file system activity indicating attempts to read browser/config files.
- Network traffic analysis looking for suspicious POST requests containing stolen archives.
## Mitigation Strategies
- Multi-Factor Authentication (MFA) deployment on all critical services.
- Use of endpoint protection capable of detecting known Lumma file structures or execution patterns.
## Related Tools/Techniques
- Other infostealers like RedLine Stealer or Vidar.
***
# Tool/Technique: PXRECVOWEIWOEI 0bj3ctivityStealer
## Overview
PXRECVOWEIWOEI 0bj3ctivityStealer is an infostealer malware variant analyzed in late September 2024. The name suggests either a highly randomized filename or a specific internal designation.
## Technical Details
- Type: Malware family (Infostealer)
- Platform: Not specified, assumed Windows based on other tools listed.
- Capabilities: Designed to steal sensitive data from compromised hosts.
- First Seen: Activity referenced from 2024-09-21.
## MITRE ATT&CK Mapping
- TA0006 - Credential Access
- T1555 - Credentials from Password Stores
- TA0010 - Exfiltration
- T1567 - Exfiltration Over Web Service
## Functionality
### Core Capabilities
- Credential harvesting.
- Data staging prior to exfiltration.
### Advanced Features
- The unique naming convention might suggest a compiled, potentially custom packer or obfuscator attempting to evade signature detection.
## Indicators of Compromise
- File Hashes: N/A
- File Names: PXRECVOWEIWOEI (as a potential identifier/component)
- Registry Keys: N/A
- Network Indicators: N/A
- Behavioral Indicators: Attempts to enumerate system files/data repositories suitable for theft.
## Associated Threat Actors
- Unknown actors utilizing this specific toolset instance.
## Detection Methods
- Heuristic analysis targeting structures common to credential-stealing malware.
- Inspection of binaries that execute with high randomness in naming or structure.
## Mitigation Strategies
- Regular password rotation schedules.
- Browser security settings hardened to prevent automatic credential storage.
## Related Tools/Techniques
- Lumma Stealer (Analyzed concurrently).
- Other custom or lesser-known infostealers.