Sophisticated RAT Hides Behind P. Diddy Scandal Lures

Summary: Threat actors are exploiting public interest in the scandal surrounding Sean “Diddy” Combs to distribute spyware disguised as files that claim to reveal deleted social media posts. Researchers have identified a variant of the PySilon RAT, named “PdiddySploit,” embedded in these files, posing significant security risks.

Threat Actor: Unknown | unknown
Victim: General public | Sean “Diddy” Combs

Key Point :

  • Attackers are leveraging the scandal surrounding Combs to lure users into downloading malicious files.
  • The PySilon RAT can steal sensitive information, record keystrokes, and execute remote commands, posing serious threats to security.
  • Users are advised to avoid downloading suspicious files and verify sources before accessing content related to trending topics.
  • Phishing emails remain a primary method for spreading malware, especially those related to celebrity scandals.

Threat actors are using the public’s interest in a current scandal surrounding celebrity rapper Sean “Diddy” Combs to spread spyware, via files promising to reveal details of deleted posts related to Combs from the X social media platform.

Researchers have uncovered a version of the open source PySilon RAT, a remote access Trojan called “PdiddySploit” hiding in files posted online and then submitted to VirusTotal, according to analysis from Veriti Research published Sept. 24.

PySilon RAT is an advanced Python-based malware that can steal sensitive information, record keystrokes, capture screen activity, and execute remote commands, posing “serious threats to personal and organizational security,” according to the post by Veriti.

Combs (aka P. Diddy), a rapper, record producer, and entrepreneur who has been in the public eye since the 1990s, is facing multiple charges of sexual assault and misconduct in New York, which has thrust him into the recent media spotlight. One area of acute public interest are controversial posts related to Combs and alleged illicit activity on X by fellow celebrities and musicians, such as Usher and Pink, as well as Combs himself that have since been deleted, according to Veriti.

“One of the most concerning aspects of this trend is the use of files related to Combs’ social media activity, particularly from X.com,” according to the post.

Related:Millions of Kia Vehicles Open to Remote Hacks via License Plate

Specifically, the researchers uncovered files containing posts and replies from Combs’ now-deleted account on VirusTotal, where they were uploaded by a user named @lamps_apple. “These files are part of an automated process of ‘collecting posts and replies,’ but they pose a high risk because they can be easily armed with malicious payloads,” according to Veriti.

Taking Advantage of Current Events

The activity demonstrates how attackers are quick to take advantage of current events or media stories of interest to the public to spread malware by weaponizing content related to them. One clear example of this activity was during the COVID-19 pandemic, when multiple phishing and other malicious campaigns leveraged public interest in the virus and other health-related topics to spread malware.

“Given the intense media coverage surrounding P. Diddy and other public figures, attackers are using these files to lure curious users into downloading them, only to be infected with malware,” according to Veriti. “The fact that P. Diddy and others have deleted their social media content adds an additional layer of intrigue, tempting users to open these files to see what was deleted.”

Related:Pwn2Own Auto Offers $500K for Tesla Hacks

PsySilon RAT — discovered in 2022 — also has seen a surge in recent use by multiple threat actors, with more than 300 samples reported on VirusTotal since June 2023, according to Cyble Research and Intelligence Labs (CRIL). Attackers use the malware to infiltrate systems, steal information, and even control devices remotely, according to Veriti.

PsySilon RAT is currently in version 3.6 and has been detected in numerous samples that imitate software, tools, and cracks, which likely originate from phishing websites, free software-downloading websites, and the like, according to Cyble.

Given the discovery of the RAT lurking behind the cover of PdiddySploit, it’s likely that as the related scandal continues to attract attention, even more attackers will “leverage this malware to exploit public interest,” according to Veriti.

Don’t Let Curiosity Cloud Safe Judgment

It’s perfectly natural for people to take an interest in trending topics and celebrity scandals, the researchers noted. However, that doesn’t mean people should throw caution to the wind when interacting with any related files or content online.

“Curiosity can be dangerous,” Veriti researchers warned, especially as attackers are well-versed in social engineering and “are always looking for ways to exploit human nature.”

Related:Security Concerns Plague Emerging Chip Architecture

To avoid falling prey to attackers aiming to capitalize on this and other news of public interest, Veriti advised that people avoid downloading suspicious files, especially if they encounter files claiming to contain deleted posts or exclusive content related to a celebrity scandal. They should always verify the source of these or any files before downloading something from the Internet, the researchers noted.

People also should be wary of email attachments because phishing emails remain a primary way that attackers spread malware. “If you receive an email with attachments related to the P. Diddy scandal, think twice before opening it,” according to Veriti. Using up-to-date antivirus software and other protections to secure email accounts also effectively can delete malware or malicious files before they even reach someone’s inbox.

Source: https://www.darkreading.com/endpoint-security/sophisticated-rat-p-diddy-scandal-lures