{"id":2820,"date":"2021-05-22T20:21:15","date_gmt":"2021-05-23T01:21:15","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2820"},"modified":"2021-05-22T20:21:16","modified_gmt":"2021-05-23T01:21:16","slug":"strrat-new-malicious-campaign-lurks-on-the-net","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/","title":{"rendered":"STRRAT New malicious campaign lurking on the Net"},"content":{"rendered":"\n<p>Researchers at Microsoft Security Intelligence discovered a malware campaign that is spreading a Remote Access Trojan (RAT) registered as STRRAT. The RAT was designed to steal data from victims while posing as a ransomware attack. StrRAT is a Java-based remote access tool that steals browser credentials, logs keystrokes, and takes remote control of infected systems &#8211; all typical RAT behaviors.<\/p>\n\n\n\n<p>This threat has a module to download an additional payload on the infected machine according to the command of the command and control server (C2). Furthermore, something that stands out about this threat is that it has a unique feature that is not common to this type of malware: \u201ca ransomware encryption \/ decryption module\u201d that changes file names in a way that suggests that the next step is encryption. However, StrRAT does not fulfill this function, &#8220;adding the file name extension .crimson to the files without actually encrypting them&#8221;.<\/p>\n\n\n\n<p>According to Microsoft, the threat actors behind the campaign used compromised email accounts to send spam messages that contained an image posing as a PDF attachment. When the image is opened, the malicious code connects to a domain to download STRRAT RAT.<\/p>\n\n\n\n<p>To launch the campaign, the attackers used compromised email accounts to send several different emails. Some of the messages use the subject line &#8220;Outgoing payments&#8221;. Others refer to a specific payment supposedly made by the &#8220;Accounts Payable Department&#8221;, which is the way emails are signed.<\/p>\n\n\n\n<p>The version of the RAT that the researchers looked at was 1.5, which is &#8220;notably more confusing and modular than previous versions,&#8221; according to one of the tweets. However, it maintains the same backdoor functions as previous versions of StrRAT that researchers have observed. These include collecting browser passwords, executing PowerShell and remote commands, and logging keystrokes, among others, we have always said it when you receive emails that make you doubt do not open them and delete them, do not risk it.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/\">AHK, the new malicious RAT distribution campaign<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/rat-is-a-very-dangerous-malware\/\">RAT is a very Dangerous Malware<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at Microsoft Security Intelligence discovered a malware campaign that is spreading a Remote Access Trojan (RAT) registered as STRRAT. The RAT was designed to steal data from victims while posing as a ransomware attack. StrRAT is a Java-based remote access tool that steals browser credentials, logs keystrokes, and takes remote control of infected systems [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2821,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2820","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-23T01:21:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-23T01:21:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"STRRAT New malicious campaign lurking on the Net\",\"datePublished\":\"2021-05-23T01:21:15+00:00\",\"dateModified\":\"2021-05-23T01:21:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/\"},\"wordCount\":341,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Campana-nueva.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/\",\"name\":\"STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Campana-nueva.jpg\",\"datePublished\":\"2021-05-23T01:21:15+00:00\",\"dateModified\":\"2021-05-23T01:21:16+00:00\",\"description\":\"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Campana-nueva.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Campana-nueva.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strrat-new-malicious-campaign-lurks-on-the-net\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"STRRAT New malicious campaign lurking on the Net\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog","description":"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/","og_locale":"es_MX","og_type":"article","og_title":"STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog","og_description":"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....","og_url":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-23T01:21:15+00:00","article_modified_time":"2021-05-23T01:21:16+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"STRRAT New malicious campaign lurking on the Net","datePublished":"2021-05-23T01:21:15+00:00","dateModified":"2021-05-23T01:21:16+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/"},"wordCount":341,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/","url":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/","name":"STRRAT New malicious campaign lurking on the Net - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg","datePublished":"2021-05-23T01:21:15+00:00","dateModified":"2021-05-23T01:21:16+00:00","description":"Malware campaigns have always been there and they always appear new, today we have to see a new one which spreads a Rat called STRRAT.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Campana-nueva.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/strrat-new-malicious-campaign-lurks-on-the-net\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"STRRAT New malicious campaign lurking on the Net"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2820","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2820"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2820\/revisions"}],"predecessor-version":[{"id":2836,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2820\/revisions\/2836"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2821"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2820"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2820"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2820"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}