Maersk, one of the largest shipping companies in the world was recently attacked with STRRAT malware. STRRAT is a remote access trojan that runs on Java-capable of doing multiple things which were discovered in the mid of 2020. These types of trojans are delivered to the victims via phishing campaigns.
The attachment will contain a dropper, say Microsoft excel macros which downloads the final payload when opened. Unlike the usual trojans, the final payload is directly attached to phishing emails.
The above clearly shows that the email has been spoofed. Further examination of the email headers reveals additional details.
Before reaching the victim, the emails are sent through “acalpupls[.]com” and also the reply to mail is given as “ftqplc[.]in”. Both of these domains are registered in August 2021 and October 2021 respectively, making them highly suspicious.
Just like any other phishing email, this email also consists of the context of a Scheduled shipment that looks legitimate.
The attachment contains 3 files. Two of which are zip files and a png image of Maersk. The zip files hold the code for STRRAT.
On digging up on the zip attachments, the following were found.
Threat actors are creating more and more complicated variants of malware every day and affect every sector whether it be shipping transportation or any other. Threats are predicted to become higher in the upcoming years. Though STRRAT is not famous, it has the ability to perform highly critical malicious functions.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
In a resounding triumph for justice, U.S. District Judge Kathryn Kimball Mizelle has sentenced Vitalii…
Hackers are plotting to benefit from the generosity of Halloween, Thanksgiving, and Christmas shoppers using…
The LLMs (Large Language Models) are evolving rapidly with continuous advancements in their research and…
In the dynamic realm of mobile application security, cybercriminals employ ever more sophisticated forms of…
A recent campaign has been observed to be delivering DJvu ransomware through a loader that…
In a pivotal update to the Okta security incident divulged in October 2023, Okta Security…