CRIL identified Persian Remote World, a site selling a suite of malicious tools including RATs, loaders, and crypters. The collection features operational panels, free and paid variants on Telegram, and a range of capabilities such as privilege escalation, firewall manipulation, keylogging, data exfiltration, and ransomware functionality. #PersianRAT #PersianLoader #PersianCrypter #PersianRemoteWorld #Telegram #VirusTotal #Cyble
Keypoints
- CRIL uncovered Persian Remote World, a website marketing a variety of malicious tools.
- The site offers Remote Access Trojans (RATs), loaders, and crypters under different subscriptions.
- The Persian RAT includes privilege escalation and defense evasion capabilities, including UAC bypass.
-
MITRE Techniques
- [T1203] User Execution – Brief description of how it was used. Quote: “User opens the malicious software installer”
- [T1059.003] Windows Command Shell – Brief description of how it was used. Quote: “RAT can execute itself using cmd.exe”
- [T1548.002] Bypass User Account Control – Brief description of how it was used. Quote: “RAT has a module to bypass UAC”
- [T1562.004] Impair Defenses: Disable or Modify System Firewall – Brief description of how it was used. Quote: “RAT has capabilities to disable or enable Firewall”
- [T1555.003] Credentials from Web Browsers – Brief description of how it was used. Quote: “RAT can access browser data of Chrome, Firefox and Edge”
- [T1056.001] Keylogging – Brief description of how it was used. Quote: “RAT can capture keystrokes”
- [T1056.002] GUI Input Capture – Brief description of how it was used. Quote: “RAT can take screenshots”
- [T1083] File and Directory Discovery – Brief description of how it was used. Quote: “RAT can discover Games and Application files and directories”
- [T1095] Non-Application Layer Protocol – Brief description of how it was used. Quote: “RAT uses TCP for C&C communication”
- [T1041] Exfiltration Over C2 Channel – Brief description of how it was used. Quote: “Exfiltration Over C&C Channel”
- [T1486] Data Encrypted for Impact – Brief description of how it was used. Quote: “RAT has a routine to deploy ransomware in it”
Indicators of Compromise
- [MD5] Persian RAT – edb799ce59664a93495cddeed72cef6a, a3f087c21420034bd9544a2d144fbb90ca138afc, and 1 more hash
- [SHA1] Persian RAT – edb799ce59664a93495cddeed72cef6a, a3f087c21420034bd9544a2d144fbb90ca138afc, and 1 more hash
- [SHA256] Persian RAT – 43403eeb7b8ea5705c727a0fff8d714ea3e27449b6b9ba0edd12c666848e2492, and 1 more hash
- [MD5] Persian Builder – 85b82f2333b7f9b8c0e12ac86e136c67, and 1 more hash
- [SHA1] Persian Builder – 084270a306e14db5cc8540f3adc8ea1ffa511ba5, and 1 more hash
- [SHA256] Persian Builder – 4d978a6f806a95c5ee89f8a394ad2a2e4336ad6554922fcde38c46311ac17874, and 1 more hash
- [MD5] Persian Loader (Variant 1) – 185d2a857bf220f849266b717c860f99, and 1 more hash
- [SHA1] Persian Loader (Variant 1) – c123aff3567852b5fca04ee3cf40195714325ade, and 1 more hash
- [SHA256] Persian Loader (Variant 1) – 464851b14b01e9ca6ff2f6fbc12c3368e3e89bc6f37174742f6a58e20b881d6e, and 1 more hash
- [MD5] Persian Loader (Variant 2) – 79628c79d517656a9238e77d8b1f2bed, and 1 more hash
- [SHA1] Persian Loader (Variant 2) – 0f83407aaa82196929c51ff42cba49faad7a4d81, and 1 more hash
- [SHA256] Persian Loader (Variant 2) – 06c496e9d53db6b272f4443e85dfc61f934598f70dbcb78c0f0a371bf86888ed, and 1 more hash
- [MD5] Persian Loader (Variant 3) – 032df29c4c01ca8f08fd7e3006a2482b, and 1 more hash
- [SHA1] Persian Loader (Variant 3) – 85e2a9aa15a4a75a1d5a6eeb8f72ccb3b8d9a088, and 1 more hash
- [SHA256] Persian Loader (Variant 3) – d57ea1ea7bbe1894cb161e44bb109f74c8f2338601796b58fa30c2edcdae2017, and 1 more hash
Read more: https://cyble.com/blog/new-persian-remote-world-selling-a-suite-of-malicious-tools/