Hackers infecting other hackers with remote-access trojan


Hackers have turned on themselves according to a newly discovered malware campaign that suggests that they have become the targets of other hackers who have begun repackaging popular hacking tools with malware.
The multi-year campaign was first discovered by the VP of security strategy and principal researcher at Cybereason, Amit Serper who found that hackers have begun modifying existing hacking tools by injecting a powerful remote-access trojan into them. When these modified tools are opened, they give hackers full access to the target’s computer.
According to Serper, the attackers have made it quite easy to spread their repackaged tools by posting them on popular hacking forums.
However, these repackaged tools not only give hackers access to a target’s computer but they also open a backdoor to their systems which allows the attackers to utilize any other computer or network that they have already breached.
njRat trojan
During his investigation of the campaign, Serper found that the hackers behind these attacks are injecting and repackaging hacking tools with the njRat trojan. This trojan gives the attacker full access to a target’s desktop as well as to their files, passwords webcams and microphones.
njRat has been around since 2013 and it has been used frequently against targets in the Middle East. It is often spread through phishing emails and infected flash drives but recently hackers have begun to inject the malware on dormant or insecure websites to avoid being detected.
Hackers are once again using this technique to spread njRat and according to Serper, they have compromised several websites to host hundreds of njRat malware samples. In a blog post, he provided further details on this latest campaign and his investigation into the matter, saying:
“This investigation surfaced almost 1000 njRat samples compiled and built on almost a daily basis. It is safe to assume that many individuals have been infected by this campaign (although at the moment we are unable to know exactly how many). This campaign ultimately gives threat actors complete access to the target machine, so they can use it for anything from conducting DDoS attacks to stealing sensitive data off the machine. It is clear the threat actors behind this campaign are using multiple servers, some of which appear to be hacked WordPress blogs. Others appear to be the infrastructure owned by the threat group, judging by multiple hostnames, DNS data, etc.”
As this campaign has already operated for years, it will likely continue to do so while giving hackers a taste of their own medicine.
Via TechCrunch
Hackers have turned on themselves according to a newly discovered malware campaign that suggests that they have become the targets of other hackers who have begun repackaging popular hacking tools with malware. The multi-year campaign was first discovered by the VP of security strategy and principal researcher at Cybereason, Amit…
Recent Posts
- Apple announces the iPhone 16e with Apple Intelligence for $599
- A popular Japanese distraction-free writing device is coming to the US
- Rivian’s new Dune edition lets you channel your inner Fremen
- Here’s when and where you can preorder the new iPhone 16E
- The Humane AI Pin debacle is a reminder that AI alone doesn’t make a compelling product
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010