GoTo Meeting Loads Remcos RAT via Rust Shellcode Loader
Summary: IOCs:
There has been a notable rise in cyber threats exploiting legitimate software platforms to propagate malicious payloads. Among these threats is the Remcos RAT, a sophisticated remote access tool favored by cybercriminals. Cyber attackers have leveraged trusted applications like GoTo Meeting to facilitate the deployment of the Remcos RAT, employing advanced techniques to evade detection and compromise systems. Malicious actors have ingeniously exploited social engineering tactics, including the distribution of seemingly benign files such as software setups and tax-related documents in multiple languages to deceive unsuspecting users into executing malicious payloads.
One advanced technique is the LNK execution chain. This method involves the use of a malicious shortcut file masquerading as an amiable PDF file to trigger the execution of a modified GoTo Meeting executable named winsys[.]odt, appended with an ".exe" extension. While appearing legitimate, this file harbors malicious code that redirects execution flow to load a malicious Dynamic Link Library named g2m[.]dll. Crafted in Rust, this DLL employs sophisticated evasion tactics, including DLL sideloading, to circumvent traditional security measures. It utilizes shellcode and encrypted payload data to orchestrate the deployment of the Remcos RAT, enabling unauthorized remote access to compromised systems.
Security Officer Comments:
Furthermore, cybercriminals have implemented a JS infection chain to propagate the Remcos RAT. This chain initiates with a JScript file that triggers a sequence of downloads culminating in the execution of the aforementioned malware chain. These downloads often fetch obfuscated PowerShell scripts and encrypted payloads from remote servers controlled by threat actors, showcasing the intricacy of the attack vector.
Suggested Corrections:
https://www.gdatasoftware.com/blog/2024/05/37906-gotomeeting-loads-remcos
Link(s):
https://www.gdatasoftware.com/blog/2024/05/37906-gotomeeting-loads-remcos