SquirtDanger RAT Botnet
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how SquirtDanger is being delivered though there are unconfirmed reports indicating it is being delivered through spam campaigns conducted by the botnet itself. Once delivered, SquirtDanger will create and installation directory and copy itself to it. The following directories have been observed:
- %TEMP%\Microsoft_SQL_SDKs\AzureService.exe
- %TEMP%\MonoCecil\Fazathron.exe
Once this is done it will create a new instance of itself before terminating the original process. SquirtDanger will then create a new executable to act as a persistence mechanism. If the exectuable does not detect an instance of SquirtDanger present it will write a new copy to disk and spawn a new instance. The following exectuables have been observed:
- %TEMP%\MSBuild.exe
- %TEMP%\OmagarableQuest.exe
By default, SquirtDanger contains no additional functionality, instead downloading modules once installed.This is likely done to keep the initial package size small and avoid anti-virus scans. These modules provide SquirtDanger with the capability to:
- Download, upload and execute files.
- List, initiate and terminate processes.
- Take screenshots.
- Gather directory information.
- List drives.
- Steal browser passwords and cryptocurrency wallet addresses.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:55 pm