New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Indian APT exposes its Modus Operandi by infecting their own devices

New York Tech Editorial Team by New York Tech Editorial Team
January 11, 2022
in Cybersecurity
0
Indian APT exposes its Modus Operandi by infecting their own devices
Share on FacebookShare on Twitter

The IT security researchers at Malwarebytes have published a report revealing details of an ironic incident involving Patchwork APT, an Indian threat actor who exposed their entire operation after infecting their devices with a variant of BADNEWS Remote Administration Trojan (RAT).

The RAT was intended to be used by the group against its adversaries. However, the incident allowed researchers to gather information about the new variant, how the group functions, what are its aims and targets.

Ragnatela RAT + its capabilities

Dubbed Ragnatela which means spider’s web in Italian; the RAT was developed and tested in November last year. According to Malwarebytes Threat Intelligence Team, Ragnatela is capable of taking screenshots, logging keystrokes, collecting a list of files, and running apps, uploading files, and dropping payloads on the targeted devices.

Information collected from infected devices

Although researchers were able to collect information on Patchwork APT’s Modus Operandi, additional details revealed that the group uses VPN Secure and CyberGhost VPN to mask its IP address.

Furthermore, researchers were able to witness VirtualBox and VMware used by the threat actor for testing and development of its malicious software. 

Indian APT exposes its Modus Operandi by infecting  their own devices
Capabilities of Ragnatela – The keyboard used by the main host shows dual layouts (English and Indian) – Image: Malwarebytes

Pakistani researchers under attack

For your information, Patchwork (aka Chinastrats and Dropping Elephant) is an advanced persistent threat (APT) group which has been active since December 2015. The group is known for targeting political and military targets, especially those in Pakistan. 

However, a sneak peek at the latest information collected by Malwarebytes Threat Intelligence Team discloses that for the very first time the group employed malicious RTF files to carry out spear phishing attacks against faculty members in several Pakistani universities. 

What’s worth noting is that these faculty members were involved in research related to biological science and molecular medicine rather than associated with military or politics.

Indian APT exposes its Modus Operandi by infecting their own devices
One of the malicious documents used by threat actor – Image: Malwarebytes

More bad news for Pakistan

In its report, Malwarebytes has confirmed that Patchwork managed to achieve its targets by successfully compromising users/faculty members in the following institutions:

  • SHU University, Molecular medicine
  • National Defense University of Islamabad
  • Ministry of Defense- Government of Pakistan
  • International center for chemical and biological sciences
  • Faculty of Bio-Science, UVAS University, Lahore, Pakistan
  • HEJ Research Institute of Chemistry, International center for chemical and biological sciences, university of Karachi.

“Thanks to data captured by the threat actor’s own malware, we were able to get a better understanding of who sits behind the keyboard — The group makes use of virtual machines and VPNs to both develop, push updates and check on their victims. Patchwork, like some other East Asian APTs, is not as sophisticated as their Russian and North Korean counterparts,”

Threat Intelligence Team

Credit: Source link

Previous Post

Super Pumped gets a new, longer teaser with more Uber shenanigans

Next Post

Zyxel adds WiFi access point security service to its Nebula Cloud Networking solution

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
SentinelOne Remote Script Orchestration enables security teams to remotely automate custom responses

Zyxel adds WiFi access point security service to its Nebula Cloud Networking solution

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Ask Perion

Perion Launches Ask Perion to Bring AI-Powered Self-Service to Omnichannel Advertising

June 18, 2026
AI generated image courtesy of Famous Labs

Famous.ai and the Small Business Owner Who No Longer Needs Silicon Valley

June 17, 2026
Checkout customer service

Perion Selected by Best Buy Canada to Power Programmatic Retail DOOH Media Network

June 17, 2026
three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026
man in a blue coat wearing glasses

Why Human Skills Matter More Than Ever in the AI Era

May 27, 2026
essential travel gadgets

May 24, 2026

Recommended

Ask Perion

Perion Launches Ask Perion to Bring AI-Powered Self-Service to Omnichannel Advertising

June 18, 2026
AI generated image courtesy of Famous Labs

Famous.ai and the Small Business Owner Who No Longer Needs Silicon Valley

June 17, 2026
Checkout customer service

Perion Selected by Best Buy Canada to Power Programmatic Retail DOOH Media Network

June 17, 2026
three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz Perion PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media