{"id":2239,"date":"2023-12-21T22:00:00","date_gmt":"2023-12-21T22:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/battleroyal-hackers-deliver-darkgate-rat"},"modified":"2023-12-21T22:00:00","modified_gmt":"2023-12-21T22:00:00","slug":"battleroyal-hackers-deliver-darkgate-rat-using-every-trick","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/21\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick\/","title":{"rendered":"&#8216;BattleRoyal&#8217; Hackers Deliver DarkGate RAT Using Every Trick"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blteb9ce8e116bf0cb3\/6584a4951d3180040a1a5016\/Dark_gate-Karel_Tupy-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This fall, an unidentified threat actor executed dozens of varied social engineering campaigns against American and Canadian organizations across a variety of industries, with the goal of infecting them with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/darkgate-operator-skype-teams-messages-distribute-malware\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the multifaceted DarkGate malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/battleroyal-darkgate-cluster-spreads-email-and-fake-browser-updates\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">a blog post this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, researchers from Proofpoint were unable to definitively say whether the perpetrator it&#8217;s calling &#8220;BattleRoyal&#8221; is a totally new actor or related to any existing one. Perhaps part of the trouble has to do with its sheer variety of tactics, techniques, and procedures (TTPs) it uses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To deliver DarkGate, and more recently the NetSupport remote control software, BattleRoyal uses phishing emails en masse, as well as fake browser updates, taking advantage of traffic distribution systems (TDSs), malicious VBScript, steganography, and a Windows Defender vulnerability along the way. To date, though, none of these tactics have led to any known successful exploitations.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">BattleRoyal&#8217;s TTPs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sometimes, BattleRoyal does its social engineering via fake browser updates. Researchers <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/watch-out-attackers-hiding-malware-browser-updates\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">first observed this activity<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, tracked as &#8220;RogueRaticate,&#8221; in mid-October. In these cases, the attacker injects requests into domains it secretly controls, using content style sheets (CSS) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/espionage-steganographic-backdoor-against-govs-stock-exchange\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">steganography<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to conceal its malicious code. The code filters traffic and then redirects targeted browser users to the fake update.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, BattleRoyal is most fond of traditional email phishing. Between September and November, it was responsible for at least 20 such campaigns representing tens of thousands of emails in all.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They typically begin with a rather garden-variety message.<\/span><\/p>\n<div><img decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_center\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick.png\" src=\"https:\/\/lh7-us.googleusercontent.com\/kVndfVd611o7cSkS1UTMb-r2ithYkNM6QRvqkjL6XwahjrQMgHS1cktNCj9nac0SnThgyuAgItkE_Aao5Bm3ybfy3TOwLojACavXfzCmfASQsoOL3nzjyq5C15jryZ2fE-_axhx1iiy0PSbiaF5LDMI?width=700&amp;auto=webp&amp;quality=10&amp;disable=upscale&amp;blur=40\" loading=\"lazy\" alt=\"Example of an email used in BattleRoyal technique\" title=\"Example of an email used in BattleRoyal technique\"><\/p>\n<p class=\"ContentImage-Link\">Source: Proofpoint<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The links contained in the body might make use of multiple TDSs \u2014 a common tool for today&#8217;s cybercriminals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Proofpoint regularly sees TDSs used by threat actors in attack chains, specifically cybercrime campaigns,&#8221; says Selena Larson, senior threat intelligence analyst at Proofpoint. &#8220;Threat actors use them to ensure the computers they want to be compromised are, and anything that doesn\u2019t meet their standards such as a bot, possible researcher, etc., will be redirected away from payload delivery.&#8221; The two most common TDSs these days, she adds, are the same ones used by BattleRoyal: 404 TDS, and the legitimate Keitaro TDS.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The TDSs redirect users to a URL file that takes advantage of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-36025\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">CVE-2023-36025<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an 8.8 critical <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/exploit-for-critical-windows-defender-bypass-goes-public\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">bypass vulnerability that undermines Microsoft Defender SmartScreen<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">; ironically, SmartScreen is a security feature of Windows designed to prevent users from ending up on phishing sites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BattleRoyal appears to have been exploiting CVE-2023-36025 as a zero-day, prior to its disclosure last month (and subsequent public exploit).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">DarkGate Gets Too Hot<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When double clicked, the malicious URL files bypass Windows defenses and download malicious VBScript that executes a series of shell commands. And it&#8217;s at the end of this chain where DarkGate lies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">DarkGate is a combination loader-cryptominer-remote access Trojan (RAT). Although it&#8217;s been around for over half a decade, Larson explains, &#8220;it recently emerged around October as one of the most frequently observed malware payloads by a small set of threat actors. The recent spike in activity is likely due to the developer renting out the malware to a small number of affiliates, which they advertised on cybercriminal hacking forums.&#8221; Besides BattleRoyal, Proofpoint has observed groups it tracks as TA577 and TA571 using it, as well.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">About a month ago, BattleRoyal&#8217;s email campaigns swapped out DarkGate for NetSupport, a legitimate remote access tool that&#8217;s made the cybercriminal rounds <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/dhs-shares-data-on-top-cyber-threats-to-federal-agencies\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">for some years now<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It remains to be seen if the reason for the payload switch is due to the spike in DarkGate\u2019s popularity and the subsequent attention paid to the malware by threat researchers and the security community (which can lead to reduction of efficacy),&#8221; Larson says, &#8220;or simply a temporary change to a different payload.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/battleroyal-hackers-deliver-darkgate-rat\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This fall, an unidentified threat actor executed dozens of varied<\/p>\n","protected":false},"author":12,"featured_media":2240,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2239","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=2560%2C1709&ssl=1",2560,1709,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=640%2C428&ssl=1",640,428,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=1536%2C1025&ssl=1",1536,1025,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=2048%2C1367&ssl=1",2048,1367,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/battleroyal-hackers-deliver-darkgate-rat-using-every-trick-scaled.jpg?fit=2560%2C1709&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2239"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2239\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2240"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}