Webworm Hackers Using Modified RATs in Latest Cyber Espionage Attacks

Share:

A threat actor tracked under the moniker Webworm is taking advantage of bespoke variants of already existing Windows-based remote access trojans to fly under the radar, some of which are said to be in pre-deployment or testing phases.

“The group has developed customized versions of three older remote access trojans (RATs), including Trochilus RATGh0st RAT, and 9002 RAT,” the Symantec Threat Hunter team, part of Broadcom Software, said in a report shared with The Hacker News.

The cybersecurity firm said at least one of the indicators of compromise (IOCs) was used in an attack against an IT service provider operating in multiple Asian countries.

It’s worth pointing out that all the three backdoors are primarily associated with Chinese threat actors such as Stone Panda (APT10), Aurora Panda (APT17), Emissary Panda (APT27), and Judgement Panda (APT31), among others, although they have been put to use by other hacking groups.

Symantec said the Webworm threat actor exhibits tactical overlaps with another new adversarial collective documented by Positive Technologies earlier this May as Space Pirates, which was found striking entities in the Russian aerospace industry with novel malware.

Space Pirates, for its part, intersects with previously identified Chinese espionage activity known as Wicked Panda (APT41), Mustang Panda, Dagger Panda (RedFoxtrot), Colorful Panda (TA428), and Night Dragon owing to the shared usage of post-exploitation modular RATs such as PlugX and ShadowPad.

Other tools in its malware arsenal include Zupdax, Deed RAT, a modified version of Gh0st RAT known as BH_A006, and MyKLoadClient.

Webworm, active since 2017, has a track record of striking government agencies and enterprises involved in IT services, aerospace, and electric power industries located in Russia, Georgia, Mongolia, and several other Asian nations.

Attack chains involve the use of dropper malware that harbors a loader designed to launch modified versions of Trochilus, Gh0st, and 9002 remote access trojans. Most of the changes are intended to evade detection, the cybersecurity firm said, noting initial access is achieved via social engineering with decoy documents.

“Webworm’s use of customized versions of older, and in some cases open-source, malware, as well as code overlaps with the group known as Space Pirates, suggest that they may be the same threat group,” the researchers said.

“However, the common use of these types of tools and the exchange of tools between groups in this region can obscure the traces of distinct threat groups, which is likely one of the reasons why this approach is adopted, another being cost, as developing sophisticated malware can be expensive in terms of both money and time.”

https://thehackernews.com/2022/09/webworm-hackers-using-modified-rats-in.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:07 am, Jul 9, 2025
weather icon 15°C
L: 14° | H: 17°
broken clouds
Humidity: 70 %
Pressure: 1019 mb
Wind: 5 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 59%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 17°°C 0.18 mm 18% 7 mph 65 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
15° | 15°°C 0 mm 0% 3 mph 65 % 1019 mb 0 mm/h
Today 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 60 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 4 mph 67 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,941.18
0.60%
Ethereum(ETH)
€2,231.28
2.87%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
1.66%
Solana(SOL)
€129.54
2.01%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145847
1.82%
Shiba Inu(SHIB)
€0.000010
2.03%
Pepe(PEPE)
€0.000009
2.99%
Scroll to Top