{"id":3474,"date":"2021-08-12T23:13:28","date_gmt":"2021-08-13T04:13:28","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3474"},"modified":"2021-08-12T23:13:29","modified_gmt":"2021-08-13T04:13:29","slug":"fatalrat-trojan-that-spreads-via-telegram","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/","title":{"rendered":"FatalRAT &#8211; Trojan that spreads via Telegram"},"content":{"rendered":"\n<p>AT&amp;T Alien Labs has published a report that provides details of the new FatalRAT Trojan circulating online that aims to distribute compromised links on Telegram channels. A RAT is a Trojan that gains remote and generally unrestricted access to a target. The main objective of this type of malware is the exfiltration of data. This new malware, called FatalRAT, can be run remotely, uses defense evasion techniques, gains system persistence, logs user keystrokes, collects system information, and exfiltrates data through a command and control channel. Telegram encryption.<\/p>\n\n\n\n<p>Before the malware completely infects a system, it runs various tests, looking for virtual machine products and checking disk space and the number of physical processors, AT&amp;T Alien Labs notes. \u00abIf the machine passes the AntiVM malware tests, then FatalRAT will start its malicious activity. An AntiVM test detects virtual machine configuration files, executables, registry entries, or other flags to manipulate its original flow of execution. Something we should know about FatalRAT is that it performs the following actions:<\/p>\n\n\n\n<p><strong><em>\u25b8In the initial stage of the attack, FatalRAT performs several tests to determine if it is running on a virtual machine or not, the number of physical processors and to verify the disk space.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The point at which it initializes its malicious task is when the machine passes the AntiVM tests.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8If a user wants to use the DisableLockWorkstation registry key to lock the device through CTRL + ALT + DELETE, this will not let you because the Trojan will activate a keylogger. <\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The configuration strings containing the C2 address, the new malware, and the service name are decrypted separately.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The victim&#8217;s information is sent to the C2 server, but before reaching the servers, it uses a defense evasion technique to identify the system&#8217;s security products.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The data sent to the C2 is encrypted and distributed through port 8081.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Telegram channels are used to convey messages to a large audience. But unlike Telegram groups, only administrators can send messages through the channel.<\/em><\/strong><\/p>\n\n\n\n<p>This threat is quite persistent, in addition it has a defense evasion technique, which is responsible for identifying all the security products that run on the infected machine, going through all the running processes and looking for the existence of a predefined list of security products, the researchers note. And to make it easier for the attacker to detect installed security products, the RAT converts the process name to a product name before sending the list to the C2 server.<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/remcos-rat-a-threat-lurking-the-internet\/\">Remcos RAT Threat Lurking the Internet<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/solarmarker-is-a-trojan-that-aids-itself-with-a-rat\/\">SolarMarker is a Trojan that aids itself with a RAT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AT&amp;T Alien Labs has published a report that provides details of the new FatalRAT Trojan circulating online that aims to distribute compromised links on Telegram channels. A RAT is a Trojan that gains remote and generally unrestricted access to a target. The main objective of this type of malware is the exfiltration of data. This [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3475,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3474","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-13T04:13:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-13T04:13:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"710\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"FatalRAT &#8211; Trojan that spreads via Telegram\",\"datePublished\":\"2021-08-13T04:13:28+00:00\",\"dateModified\":\"2021-08-13T04:13:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/\"},\"wordCount\":436,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/FatalRat.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/\",\"name\":\"FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/FatalRat.jpg\",\"datePublished\":\"2021-08-13T04:13:28+00:00\",\"dateModified\":\"2021-08-13T04:13:29+00:00\",\"description\":\"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/FatalRat.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/FatalRat.jpg\",\"width\":710,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fatalrat-trojan-that-spreads-via-telegram\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FatalRAT &#8211; Trojan that spreads via Telegram\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog","description":"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/","og_locale":"es_MX","og_type":"article","og_title":"FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog","og_description":"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......","og_url":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-13T04:13:28+00:00","article_modified_time":"2021-08-13T04:13:29+00:00","og_image":[{"width":710,"height":400,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"FatalRAT &#8211; Trojan that spreads via Telegram","datePublished":"2021-08-13T04:13:28+00:00","dateModified":"2021-08-13T04:13:29+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/"},"wordCount":436,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/","url":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/","name":"FatalRAT - Trojan that spreads via Telegram - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg","datePublished":"2021-08-13T04:13:28+00:00","dateModified":"2021-08-13T04:13:29+00:00","description":"Today we will see and analyze everything that is known about a new Trojan that spreads via Telegram which was known as FatalRAT......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/FatalRat.jpg","width":710,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/fatalrat-trojan-that-spreads-via-telegram\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"FatalRAT &#8211; Trojan that spreads via Telegram"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3474"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3474\/revisions"}],"predecessor-version":[{"id":3529,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3474\/revisions\/3529"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3475"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}