Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT

Teilen:

Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT.

Among the software in question are various instruments for fine-tuning CPUs, graphic cards, and BIOS; PC hardware-monitoring tools; and some other apps, cybersecurity vendor Doctor Web said in an analysis.

Such installers are used as a decoy and contain not only the software potential victims are interested in, but also the trojan itself with all its components.

The exact initial access vector used in the campaign is unclear but it could potentially range from phishing to drive-by downloads to malicious ads. Users who land on the fake site are prompted to download a ZIP installer package.

The installer, besides activating the standard installation process, stealthily drops the Fruity trojan, a Python-based malware that unpacks an MP3 file (Idea.mp3) to load an image file (Fruit.png) to activate the multi-stage infection.

This image file uses the steganography method to hide two executables (.dll libraries) and the shellcode for the next-stage initialization inside it, Doctor Web said.

Fruity is also designed to bypass antivirus detection on the compromised host and ultimately launch the Remcos RAT payload using a technique called process doppelgänging.

That said, the attack sequence could be exploited to distribute all kinds of malware, which makes it imperative that users stick to downloading software only from trustworthy sources.

The development comes as Bitdfender disclosed details of a malspam campaign delivering the Agent Tesla malware to harvest sensitive data from compromised endpoints.

It also follows a surge in malvertising operations that have targeted customers and businesses with tainted software boosted via ads on search engines.

This includes a new wave of attacks dubbed Nitrogen in which fraudulent ISO archives are distributed using bogus ads that impersonate download pages for applications such as AnyDesk, WinSCP, Cisco AnyConnect, Slack, and TreeSize.

This malvertising campaign leads to the propagation of the infection after initial exposure, Bitdefender researchers Victor Vrabie and Alexandru Maximciuc said.

For as long as they dwell in the victim’s network, the attackers’ primary goal is to obtain credentials, set up persistence on important systems and exfiltrate data, with extortion as the end goal.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:36 pm, Mai 18, 2025
Wetter-Symbol 16°C
L: 14° | H: 18°
wenige Wolken
Luftfeuchtigkeit: 59 %
Druck: 1019 mb
Wind: 4 mph NW
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 13%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:04 am
Sonnenuntergang: 8:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 18°°C 0 mm 0% 7 mph 64 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 7 mph 59 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 6 mph 56 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0 mm 0% 6 mph 64 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,099.20
0.93%
Ethereum(ETH)
€2,248.26
1.69%
Fesseln(USDT)
€0.90
0.00%
XRP(XRP)
€2.14
2.39%
Solana(SOL)
€153.68
2.76%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.200758
4.51%
Shiba Inu(SHIB)
€0.000013
4.19%
Pepe(PEPE)
€0.000012
8.05%
Peanut das Eichhörnchen(PNUT)
€0.306420
15.37%
Nach oben scrollen