China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT

As part of a cyber espionage campaign aimed at the Asia-Pacific area this year, the China-linked BlackTech hacking gang deployed a remote access trojan (RAT) called Deuterbear, about which cybersecurity researchers have learned more.

According to a recent investigation by Trend Micro researchers Pierre Lee and Cyris Tseng, Deuterbear exhibits improvements over Waterbear despite sharing many similarities, such as support for shellcode plugins, avoiding handshakes for RAT operation, and using HTTPS for C&C connection.

In contrast to Waterbear, Deuterbear has anti-memory scanning, shares a traffic key with its downloader, and employs a shellcode format.

The larger cybersecurity community also keeps an eye on BlackTech read more China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *