Gh0stCringe Remote Access Trojan
First observed in December 2018, Gh0stCringe (also known as cineregRAT) is a remote access trojan (RAT) believed to be based on the older Gh0stRAT malware.
Summary
First observed in December 2018, Gh0stCringe (also known as cineregRAT) is a remote access trojan (RAT) believed to be based on the older Gh0stRAT malware.
Affected platforms
The following platforms are known to be affected:
Threat details
Despite having full RAT capabilities, Gh0stCringe appears to be used solely as a dropper in cryptocurrency mining campaigns, most notably for MadoMiner, suggesting it may be shared amongst several disparate attackers.
Gh0stCringe is typically distributed over SMB or EternalBlue and DoublePulsar amongst others) but has also been observed as a payload in spam campaigns. Once delivered to a target system, Gh0stCringe will load itself into memory to prevent detection and analysis, before installing five function modules as a service group to maintain persistence.
Once installed, Gh0stCringe will connect to a command and control server and send XOR encrypted system information before awaiting further instructions. Secondary payloads are sent from the C2 server as DLL files and installed as services in a similar manner to Gh0stCringe itself. Gh0stCringe can also create proxy servers and delete event logs on affected systems, although this functionality has not been observed in the wild.
Remediation steps
| Type | Step |
|---|---|
|
Both the EternalBlue and DoublePulsar exploits are addressed in Microsoft Security Bulletin MS17-010. Users are advised to install this update immediately if they have not already done so. If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
Additionally, to prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:52 pm