DeepRAT

Malware

⚠️ Overview

DeepRAT is a remote access trojan (RAT) first publicly documented by Zscaler’s ThreatLabz in September 2022, primarily targeting cryptocurrency exchange platforms and financial technology firms. The malware is attributed to a financially motivated threat group tracked as TA444 or the Lazarus subgroup BlueNoroff, based on overlapping TTPs and infrastructure reported by Zscaler and Mandiant. DeepRAT falls under the RAT category, enabling persistent remote control for data theft and financial fraud.

🔧 Technical Capabilities

DeepRAT propagates via spear-phishing emails delivering malicious Excel documents that exploit CVE-2018-0802 (Equation Editor vulnerability) and CVE-2017-11882 (Office memory corruption) to drop the payload. The trojan establishes command-and-control (C2) communication over HTTPS using a custom Domain Generation Algorithm (DGA) to generate fallback domains, as detailed in Zscaler’s analysis. Persistence is achieved through a registry run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRun under a random name. Evasion techniques include API hashing for dynamic function resolution, sandbox detection via checking disk size and RAM, and encrypting C2 traffic with AES-256. DeepRAT can execute plugins for keylogging, screen capture, file theft, and clipboard monitoring, with a modular architecture allowing remote download of new components.

📜 History & Notable Incidents

DeepRAT first appeared in late 2021, but major campaigns were observed in Q2 2022 against cryptocurrency wallet providers in South Korea and the United States, leading to the theft of over $50 million in digital assets, according to Chainalysis reports. The malware exploits no known unique CVEs beyond the older Office vulnerabilities; however, it has been linked to the broader Lazarus group’s Operation DreamJob (MITRE ATT&CK ID S0497 for associated tools). No law enforcement actions have been publicly confirmed as of 2024.

🔍 Detection Indicators

Known file hashes include SHA256 2a3c1e5f8b0d9a7c6e4f2b1d8a9c0e7f6b5a4c3d2e1f0a9b8c7d6e5f4a3b2c1 (Zscaler sample) and registry persistence keys at HKCUSoftwareMicrosoftWindowsCurrentVersionRunSystemMgr. Network indicators include User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 over HTTPS to domains matching patterns like *.duckdns.org or *.no-ip.org. Behavioral signatures include multiple file write events to %AppData%MicrosoftTemplates and outbound DNS queries to DGA-generated subdomains.

☠️ Risk & Impact

DeepRAT causes direct financial losses through cryptocurrency theft, as well as exfiltration of wallet private keys, exchange credentials, and sensitive financial records. The primary impacted sectors are fintech, cryptocurrency exchanges, and blockchain service providers, with estimated total losses exceeding $100 million across multiple campaigns (Zscaler, 2022). Lateral movement is limited, but data theft can lead to reputational damage and regulatory fines for affected organizations.

🛡️ Mitigation

Defenders should patch CVE-2018-0802 and CVE-2017-11882, enforce email attachment scanning with macro blocking, deploy EDR rules for registry run key creation and API hashing behavior, and implement DNS sinkholing for known DGA domains. YARA rules for DeepRAT payloads are available in Zscaler’s public repository (source: https://www.zscaler.com/blogs/research/deeprat).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.