Saefko Remote Access Trojan
First observed in 2019, Saefko is a .NET remote access trojan (RAT), targeting Windows and Android devices. It is available for purchase on several dark web sites and hacking forums.
Summary
First observed in 2019, Saefko is a .NET remote access trojan (RAT), targeting Windows and Android devices. It is available for purchase on several dark web sites and hacking forums.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Saefko is delivered. However, there are unconfirmed reports suggesting it may be delivered via compromised USB devices.
Once infected, Saefko alters registry entries to ensure persistence across reboots, executing every time a user logs in. Saefko then fetches the user's Chrome browser history looking for specific types of activities, such as those involving banking, business, social media, gaming, cryptocurrency and shopping. It sends the collected data to its command and control server and requests further instruction. Saefko has the following additional capabilities:
- Extract system information and log data.
- Takes screenshots.
- Record system audio and video.
- Log keystrokes.
- Download, upload, and execute files.
- Copy itself to any removable USB devices.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:59 pm