The Solar 4RAYS Cyber ​​Threat Research Center has discovered a unique GoblinRAT virus that has been attacking Russian departments and IT companies serving the public sector for at least three years. This was reported by RB.RU in the press service of the Solar group of companies.

The Solar Group reported on a unique virus that had been attacking Russian departments for three years
  1. News

Author:

Subscribe to RB.RU on Telegram

They added that with the help of this malware, the attackers gained full control over the victims’ infrastructure and the first traces of infection date back to 2020. Now GoblinRAT has been removed from the attacked networks, Solar said.

The virus was first discovered in 2023 during an investigation into an incident at one of the IT companies. Their internal cybersecurity specialists noticed the deletion of system logs on one of the servers and the downloading of a utility to steal account passwords from a domain controller. Employees launched an investigation and hired experts from Solar 4RAYS.

Specialists at the Cyber ​​Threat Research Center discovered malicious code masquerading as a legitimate application process. The parameters of the malicious process did not stand out in any way and the file that started it differed from the legitimate one by a single letter in the name.

A more detailed analysis revealed that GoblinRAT does not have automatic fixing functions: each time, the hackers first studied the characteristics of the target infrastructure (software used and others) and then introduced the virus under the guise of one of the applications that were installed. run on the specific system that is running. attacked.

In total, GoblinRAT was detected in four organizations and in each of them the attackers gained remote access with administrator rights to all network segments. Solar 4RAYS experts found evidence indicating that in at least one of the attacked infrastructures, hackers had that access for three years, with the shortest attack with this virus lasting approximately six months.

We answer questions about the anti-money laundering law and tell you what to do if you encounter restrictions in the course “The most important thing about 115-FZ”.

Author:

Bogdan Muzychenko

Source: RB

Previous articleUsers from 29 cities complained on November 8 about a failure in the operation of the Bank of Saint Petersburg
Next article*Facebook asked the Supreme Court to reject the fraud claim Applications08 November 2024, 14:15
I am a professional journalist and content creator with extensive experience writing for news websites. I currently work as an author at Gadget Onus, where I specialize in covering hot news topics. My written pieces have been published on some of the biggest media outlets around the world, including The Guardian and BBC News.

LEAVE A REPLY

Please enter your comment!
Please enter your name here