216.73.216.226

Malware Analysis Reveals Sophisticated RAT With Corrupted Headers

· Published 29/05/2025 16:10 · Modified 29/05/2025 19:34

Export JSON

Essential information

Published
29/05/2025 16:10
Modified
29/05/2025 19:34
Tags
2025-05-29 api mapping corrupted headers remote access trojan tls transmission
Related entities
13 techniques (mitre), 1 malware

Description

A sophisticated (RAT) has been discovered operating within a legitimate Windows process, using advanced evasion techniques. The malware's PE and DOS headers were deliberately corrupted, making traditional analysis difficult. Fortinet's FortiGuard Incident Response Team analyzed the malware using a full memory dump, recreating the compromised environment. The RAT's features include screenshot capture, remote server mode, and service control. It uses over 250 Windows APIs, encrypts C2 communications, and employs custom XOR-based encryption. The analysis highlights the need for enhanced security measures, including monitoring of legitimate processes, memory analysis tools, and network traffic analysis to defend against such sophisticated threats.

External references