Telefonica Tech UK
Win+R Exploitation Techniques for Remote Access Trojans
Pages
12
Time to read
9 mins
Publication
Language
English
Pages
12
Time to read
9 mins
Publication
Language
English
This document is a technical report that details the exploitation technique of the 'Windows + R' attack vector utilized by the threat group known as 'Rogue Raticate'. The report outlines the steps of the attack, starting with social engineering to execute a PowerShell command through the MSHTA.EXE application. It presents a comprehensive analysis of the attack's methodology, including file delivery, installation processes, and the indicators of compromise. The attacker utilizes obfuscated JavaScript to download various files necessary for the installation of the NetSupport Remote Access Trojan. The report also discusses the configuration settings that facilitate stealth and persistence of the malware on the compromised system. Furthermore, it emphasizes the importance of disabling the Windows + R shortcut in corporate environments to mitigate associated risks and highlights the necessity for robust security measures to counter evolving threats. Overall, this technical report serves as a guide for understanding and defending against such attack vectors.