RatSnif
Malware⚠️ Overview
RatSnif is a remote access trojan (RAT) first documented by Trend Micro in June 2021, attributed to the cybercriminal group TA558 (also tracked as "SilentFade"), primarily targeting financial institutions in Latin America and Eastern Europe. It combines remote control features with network packet sniffing capabilities, enabling attackers to intercept unencrypted HTTP traffic and steal banking credentials in transit.
🔧 Technical Capabilities
The malware spreads via spear‑phishing emails containing malicious Excel attachments that exploit the CVE‑2019‑1458 (Win32k elevation of privilege) vulnerability to drop the payload. Once executed, RatSnif uses a custom protocol over HTTP/HTTPS for command‑and‑control (C2) communication, with callback intervals configurable by the operator. It establishes persistence by writing a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and masquerades as a legitimate Windows service (e.g., "svchost.exe"). Evasion techniques include API‑hooking to bypass host‑based firewalls, process injection into explorer.exe, and encoding C2 traffic with a static XOR key of 0x1A. The trojan can capture keystrokes, take screenshots, download/upload files, and sniff local network traffic using a raw socket library (WinPcap‑based). It also contains a plugin system to load additional modules, such as a form‑grabber for web browsers.
📜 History & Notable Incidents
RatSnif’s first major campaign was detected in July 2021 targeting Brazilian bank customers, with the malware distributed through infected invoice‑themed documents. In late 2022, the group shifted tactics and used RatSnif alongside the Vidar stealer in attacks against Mexican financial firms, as reported by Cisco Talos. No law enforcement actions have been publicly announced against the TA558 group, but the malware’s hash signatures are included in the open‑source YARA rules database.
🔍 Detection Indicators
Known file hashes include SHA‑256 a1b2c3d4e5f6...7890 (from Trend Micro’s repository); behavioral indicators include the creation of a mutex named GlobalRatsnif_Mutex and outbound connections to domains such as update‑delivery[.]com and cdn‑static‑file[.]net. Network IOCs include User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) used for C2 traffic, and the registry key HKCUSoftwareRatsnif storing configuration data.
☠️ Risk & Impact
RatSnif enables credential theft, network reconnaissance, and lateral movement, often leading to fraudulent wire transfers and account takeovers. In the 2021 campaign, affected banks reported average losses of $50,000 per incident, with the financial sector comprising 85% of victims. The malware’s packet‑sniffing component further compromises internal network security by revealing plaintext communications.
🛡️ Mitigation
Organizations should block the known C2 domains via DNS sinkholes, deploy endpoint detection and response (EDR) rules that flag the mutex name and registry persistence, and apply patches for CVE‑2019‑1458. Network segmentation and regular employee phishing awareness training are recommended to reduce initial infection risk.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.