Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Symantec Finds a RAT Going After U.S., UK and India SMBs

    Written by

    Sean Michael Kerner
    Published January 21, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security firm Symantec issued a warning today about an ongoing attack against small and midsize businesses in the United States, United Kingdom and India that is infecting users with a remote access Trojan (RAT).

      A RAT enables an attacker to have remote access to a victim’s machine and can lead to information disclosure and financial loses. According to Symantec’s research, the campaign makes use of the Backdoor.Breut and Trojan.Nancrat RAT tools and has been active since the beginning of 2015.

      “The attack is one among many detected by Symantec daily,” Symantec researcher Gavin O’Gorman told eWEEK. “It was brought to our attention by a customer request.”

      According to O’Gorman, Symantec has observed hundreds of distinct machines compromised by this attack. Fifty-six percent of the victims identified by Symantec are in India, with 23 percent in the U.S. and 21 percent in the UK.

      The mechanics of the attack are relatively simple, yet effective. The attackers send phishing emails with some form of financial-related titles, such as payment advice, request for quotation and payment remittance. The phishing emails are sent from either stolen or spoofed email accounts that aim to trick potential victims. The emails contain a simple file attachment that is often compressed in the .ZIP format. Once the victim clicks on the file, the impacted system is compromised by one of the RATs.

      “The victim has to open the attachment in the email and execute the file to become infected,” O’Gorman said.

      Once a system is infected, Symantec’s research has found that the attackers can take control of it and transfer money from the victim’s account.

      The RAT campaign is not being driven by an exploit kit such as Angler, and no zero-day exploit is being used, O’Gorman noted. He added that users with a fully patched system and up-to-date antivirus product should be protected.

      “While advanced attack groups attract a lot of attention in the news, we’d like to remind businesses that less skilled attackers can still cause major damages to a targeted company,” O’Gorman said.

      Symantec is not taking any specific technical or law enforcement actions to try to stop the RAT campaign either.

      “Law enforcement was not notified because publication of an attack is often an effective method for stopping the activity,” O’Gorman said.

      Since the beginning of the Internet era, security professionals have been advising IT users not to click on suspicious links and to keep systems updated with modern antivirus tools. Still, phishing campaigns continue to be successful. O’Gorman noted that based on campaigns run by Symantec’s Phishing Readiness technology, on average, employees are susceptible to email-based attacks 18 percent of the time. The Phishing Readiness technology is a service that enables organizations to conduct simulated phishing attacks to test user reactions to potential attacks.

      “Businesses need to better educate employees to always exercise caution and to not open attachments or click on links in suspicious email,” O’Gorman said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.