ZeroHour

Search: “masquerading”

2,333 stories

Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)

SANS guest analyst detonated a RedTail Linux sample from a DShield honeypot, finding process masquerading as php-fpm, monitoring-kill behavior, and a TCP listener.

A DShield honeypot captured multi-architecture RedTail Linux executables (ARM, ARM64, i686, RISC-V, x86-64) deployed via shell scripts. Dynamic analysis of the UPX-packed, statically linked x86-64 sample (SHA-256 63be5f38...d35e) in an isolated Ubuntu 24.04 VM on Proxmox showed it renamed its process via prctl(PR_SET_NAME), killed a filesystem-monitoring process, and opened a TCP listening socket while surviving processes posed as php-fpm or PostgreSQL-like workers. Differential memory images pre- and post-execution were captured from the hypervisor for forensics.

SANS Internet Storm Center · 6d agoMalware in the wild1

ValleyRAT masquerading as adware

Kaspersky reports threat actors distributing the ValleyRAT backdoor disguised as adware, tracing the infection chain to the final payload.

Kaspersky researchers analyzed a campaign distributing the ValleyRAT backdoor under the guise of adware. The write-up documents the complete infection chain, from the malicious installer through deployment of the final backdoor payload. ValleyRAT is a remote access tool typically used by criminal actors for surveillance and data theft.

Kaspersky Securelist · 16d agoMalware in the wild