As reported by The Hacker News, a sophisticated cyber campaign is actively targeting Chinese-speaking users by employing typosquatted domains to impersonate trusted software brands. This operation is distributing a newly identified remote access trojan (RAT) known as AtlasCross RAT.The campaign, attributed to the Chinese cybercrime group Silver Fox, encompasses a wide range of applications including VPN clients, encrypted messengers, video conferencing tools, and e-commerce software. Attackers create fake websites mimicking brands like Surfshark VPN, Signal, Telegram, and Zoom, tricking users into downloading ZIP archives. These archives contain trojanized installers that deploy the AtlasCross RAT. The RAT utilizes a PowerChell framework to disable security measures like AMSI and ETW, and employs ChaCha20 encryption for its command-and-control (C2) traffic. It also features capabilities for DLL injection, RDP session hijacking, and actively terminates connections with Chinese security products.The reuse of a single stolen code-signing certificate across multiple malware campaigns highlights a concerning trend of cybercriminals seeking to legitimize malicious payloads and bypass security checks. The evolution of Silver Fox's toolkit, from older RAT derivatives to the advanced AtlasCross RAT, demonstrates a continuous effort to enhance their capabilities for data theft and financial fraud.Source: The Hacker News
Encryption, Malware
AtlasCross RAT campaign targets Chinese users via typosquatted domains

(Adobe Stock Images)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



