The cybersecurity experts at the ASEC security firm have recently identified that hackers are actively targeting the vulnerable Microsoft SQL and MySQL database servers to deploy the Gh0stCringe RAT.
Gh0stCringe that is also known as CirenegRAT, is a variant of Gh0st RAT malware, this malware was mostly exploited by Chinese hackers for cyber-espionage operations between 2018 and 2020.
The first report of this RAT was made in December 2018, and distribution was accomplished through the use of an SMB vulnerability.
By compromising the database servers, the threat actors are attempting to download the malicious mcsql.exe executable to the disk via the following processes:-
By using the Microsoft SQL xp_cmdshell command the threat actors dropped Cobalt Strike beacons last February and now it has been detected that all these current attacks are identical to the Microsoft SQL server attacks.
To receive custom commands from the threat actors and exfiltrate all the stolen data to the adversaries, the Gh0stCringe RAT establishes a connection with the C2 server.
In Gh0stCringe RAT, the most aggressive element is the keylogger, as from the compromised system it steals the user inputs. Keylogging can be activated according to the settings data, or it can be controlled by a command received from the command and control server.
Apart from this, in an endless loop, the keylogging component queries the state of every key using the Windows Polling method (GetAsyncKeyState API).
Here, the malware monitors the keypresses, basic information about the system and network to send them to the command and control servers of the malware.
In total, there are 7 settings, and here below we have mentioned them all:-
Commands supported by Gh0stCringe
The remote commands that are supported by the Gh0stCringe RAT are:-
To mitigate such threat, the cybersecurity analysts at ASEC has recommended the following mitigations:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…