Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tech News BitRAT malware now spreading as a Windows 10 license Medicines

Qv1K05.jpg

A new BitRAT malware distribution campaign is underway, exploiting users looking to activate pirated Windows OS versions for free using unofficial Microsoft license Medicines.

BitRAT is a powerful remote access trojan sold on cybercrime forums and dark web markets for as low as $20 (lifetime access) to any cybercriminal who wants it.

As such, each buyer follows their own approach to malware distribution, ranging from phishing, watering holes, or trojanized software.

Targeting pirates with malware
In a new BitRAT malware distribution campaign discovered by researchers at AhnLab, threat actors are distributing the malware as a Windows 10 Pro license Medicines on webhards.

Webhards are online storage services popular in South Korea that have a steady influx of visitors from direct download links posted on social media platforms or Discord. Due to their wide use in the region, threat actors are now more commonly using webhards to distribute malware.

The actor behind the new BitRAT campaign appears to be Korean based on some of the Korean characters in the code snippets and the manner of its distribution.

Qv1OWm.jpg

Post promoting the BitRAT dropping Windows Medicines (ASEC)


To properly use Windows 10, you need to purchase and activate a license with Microsoft. While there are ways to get Windows 10 for free, you still need a valid Windows 7 license to get the free upgrade.

Those who do not want to deal with licensing issues or do not have a license to upgrade commonly turn to pirating Windows 10 and using unofficial Medicines, many of which contain malware.

In this campaign, the malicious file promoted as a Windows 10 Medicines is named 'W10DigitalActiviation.exe' and features a simple GUI with a button to "Activate Windows 10."

Qv1gyA.jpg

The malware downloader posing as a Windows Medicines (ASEC)

However, instead of activating the Windows license on the host system, the "Medicines" will download malware from a hardcoded command and control server operated by the threat actors.

The fetched payload is BitRAT, installed in %TEMP% as ‘Software_Reporter_Tool.exe’ and added to the Startup folder. The downloader also adds exclusions for Windows Defender to ensure that BitRAT won’t encounter detection issues.

Once the malware installation process is completed, the downloader deletes itself from the system leaving behind only BitRAT.

Qv1ouR.jpg

The downloader fetching the BitRAT payload (ASEC)

A versatile RAT
BitRAT is promoted as a powerful, inexpensive, and versatile malware that can snatch a wide range of valuable information from the host, perform DDoS attacks, UAC bypass, etc.

BitRAT supports generic keylogging, clipboard monitoring, webcam access, audio recording, credential theft from web browsers, and XMRig coin mining functionality.

Additionally, it offers remote control for Windows systems, hidden virtual network computing (hVNC), and reverse proxy through SOCKS4 and SOCKS5 (UDP). On that front, ASEC’s analysts have found strong code similarities with TinyNuke, and its derivative, AveMaria (Warzone).

The hidden desktop feature on these RATs is so valuable that some hacking groups, like the Kimsuky, incorporated them in their arsenal just to use the hVNC tool.

Risk of piracy
Even if the legal and ethical aspects are ignored, using pirated software is always a security gamble.

The more tools are used to activate illegally obtained copies of software or Medicines their intellectual property protection systems, the greater the chances of ending up with a nasty malware infection.

Those who can’t afford to purchase a Windows license should look at alternative options instead, such as accepting the limitations of the free version, monitoring for special offers from trustworthy platforms, or using Linux.

Ultimately, users should not trust license Medicines and any unsigned executable authored and released by unknown vendors to run on your system.
 
Last edited by a moderator:

Redlin3

Member
Banned
Downloaded
18.5 GB
Uploaded
89.5 MB
Ratio
0
Seedbonus
0
Upload Count
0 (0)
Member for 2 years
Really need to check everything before you install onto your main host. i have a cracked version of bitrat and even the rat itself has malware by the developer. Those using it get infected by other virus or get their information stolen. Thanks for this information would really help people in case of anything.
 

RedDove

⭐ VIP
Power User
✅ Verified Member
Member
Downloaded
118.2 GB
Uploaded
41.6 TB
Ratio
360.28
Seedbonus
1,839,165
Upload Count
0 (0)
Member for 9 years
I agree, we should check everything we download especially if you're planning
to use that item where you have sensitive material stored. I don't search the web
for files for my PC. I come here or I physically walk in a store and buy it.
I don't trust so easy, I don't care what kind of deals people offer, I'd rather pay
full price from a trusted source.
TeamOS, is one of the only place I trust on the net, they haven't let me down.

Thank you, ph4nt0m, for this info. :)
There really are some snake in the grass excuses for human beings,
or should I say, so called retailers out there hiding behind the guise of kindness
or giving you that awesome deal you just can't refuse.
Locked out of your phone or PC, I have the perfect software for you,
for the one time price of $19.99 plus tax. and it's yours. Next thing you know, your identity
is being sold on the black market etc. Yeah, they're snakes, no, that's an insult to
the snake.

Anyway, thanks again, very much, for this info. :)
 

ph4nt0m

D4RK SH4D0W
Power User
✅ Verified Member
Member
Downloaded
689.1 GB
Uploaded
10.1 TB
Ratio
14.98
Seedbonus
3,230,844
Upload Count
0 (0)
Member for 9 years
I agree, we should check everything we download especially if you're planning
to use that item where you have sensitive material stored. I don't search the web
for files for my PC. I come here or I physically walk in a store and buy it.
I don't trust so easy, I don't care what kind of deals people offer, I'd rather pay
full price from a trusted source.
TeamOS, is one of the only place I trust on the net, they haven't let me down.

Thank you, ph4nt0m, for this info. :)
There really are some snake in the grass excuses for human beings,
or should I say, so called retailers out there hiding behind the guise of kindness
or giving you that awesome deal you just can't refuse.
Locked out of your phone or PC, I have the perfect software for you,
for the one time price of $19.99 plus tax. and it's yours. Next thing you know, your identity
is being sold on the black market etc. Yeah, they're snakes, no, that's an insult to
the snake.

Anyway, thanks again, very much, for this info. :)
it's our duty to keep safe our family so no need to say thanks take care :)
 
Last edited:

Tonee Lim

✅ Verified Member
Member
Downloaded
2 TB
Uploaded
21.1 TB
Ratio
10.38
Seedbonus
539,425
Upload Count
0 (0)
Member for 6 years
TY:h: for the info. - would have been better with some clear "Steps on how to check if you got infected or have this in your system and how to remove it" advice...but...knowing is a 4th of the battle TYTY ;)
 

pinkfloyder

pinkfloyder
✅ Verified Member
Member
Downloaded
387.7 GB
Uploaded
1.1 TB
Ratio
2.89
Seedbonus
1,748
Upload Count
0 (0)
Member for 10 years
Great info ph4nt0m, many thanks for this. Lets all try to stay safe!!
 

mobi0001

The Power Is Yours!!!
Uploader
Power User
✅ Verified Member
Member
Downloaded
62.3 GB
Uploaded
11.3 TB
Ratio
186
Seedbonus
975
Upload Count
89 (104)
Member for 3 years
BTW, where does it get installed post downloading? I could not find a reference to its location. That would be helpful if those researchers gave that info.

On a separate note, most of these rats are asked to be run by biggies, afair my old news. Maybe, maybe not, but still.
 

Redlin3

Member
Banned
Downloaded
18.5 GB
Uploaded
89.5 MB
Ratio
0
Seedbonus
0
Upload Count
0 (0)
Member for 2 years
BTW, where does it get installed post downloading? I could not find a reference to its location. That would be helpful if those researchers gave that info.

On a separate note, most of these rats are asked to be run by biggies, afair my old news. Maybe, maybe not, but still.
Where this specific malware gets installed or the windows license Medicines program? Because i've tinkered with it and its mostly installed onto your %APPDATA% or %PROGRAMFILES% directory. ALWAYS check if the program needed administrator elevation then its mostly hidden programfiles or any inconspicuous location. You can also bypass admin all together! This malware is very tedious as it can crash your computer if you try to disable using task manager. And it may even hide from the list. Install something like Glasswire to monitor your traffic and any program requesting a domain not related to microsoft services or the program your using then it may be malware.

Send me any file you think may have malware and i can reverse engineer its binary data to find out which malware sample it is. Most malware is encrypted per say so its a lot of work but can be done.
 

mobi0001

The Power Is Yours!!!
Uploader
Power User
✅ Verified Member
Member
Downloaded
62.3 GB
Uploaded
11.3 TB
Ratio
186
Seedbonus
975
Upload Count
89 (104)
Member for 3 years
Where this specific malware gets installed or the windows license Medicines program? Because i've tinkered with it and its mostly installed onto your %APPDATA% or %PROGRAMFILES% directory. ALWAYS check if the program needed administrator elevation then its mostly hidden programfiles or any inconspicuous location. You can also bypass admin all together! This malware is very tedious as it can crash your computer if you try to disable using task manager. And it may even hide from the list. Install something like Glasswire to monitor your traffic and any program requesting a domain not related to microsoft services or the program your using then it may be malware.

Send me any file you think may have malware and i can reverse engineer its binary data to find out which malware sample it is. Most malware is encrypted per say so its a lot of work but can be done.
I did check almost every folder. But yeah, there were few ms folders which need elevated privilege to open. I will recheck to see how much more I can find out. Will reach out to you if I find anything, though I trust @FBConan whose builds I have been using and Medicines provided by him. Still to be safe. ?
 

Redlin3

Member
Banned
Downloaded
18.5 GB
Uploaded
89.5 MB
Ratio
0
Seedbonus
0
Upload Count
0 (0)
Member for 2 years
I did check almost every folder. But yeah, there were few ms folders which need elevated privilege to open. I will recheck to see how much more I can find out. Will reach out to you if I find anything, though I trust @FBConan whose builds I have been using and Medicines provided by him. Still to be safe. ?
It's much more harder when trying to investigate a custom os. IT may be using a ROOTKIT not saying it is. But windows can run scripts when running installation so you may never know unless researched.
I wouldn't worry about it too much, multiple user installing will notice if anything is going on will report. Just never use a custom os as a main unless for gaming only or a specific reason. DO NOT BANK or enter any personal information you should be alright most damage would be a cpu/gpu miner and you can always notice that installed when your idle or nvidia tells you :)
 

rajeshkumar95

Member
Downloaded
7.8 GB
Uploaded
4.5 GB
Ratio
0.58
Seedbonus
1
Upload Count
0 (0)
Member for 4 years
thx bro its good to know that:)
 

Holzkopf

Member
Downloaded
8.1 GB
Uploaded
5 GB
Ratio
0.62
Seedbonus
0
Upload Count
0 (0)
Member for 2 years
Thank you for sharing this important Info.
 

PsyTom

Power User
✅ Verified Member
Member
Downloaded
1.4 TB
Uploaded
502.1 TB
Ratio
367.69
Seedbonus
1,662,990
Upload Count
0 (0)
Member for 3 years
appreciate this informative share. keep up such good work.
 

Tonee Lim

✅ Verified Member
Member
Downloaded
2 TB
Uploaded
21.1 TB
Ratio
10.38
Seedbonus
539,425
Upload Count
0 (0)
Member for 6 years
Dang Koreans...sliding in all them info stealing sotware to get my secret-ultra-uber-leet-competitive noob gaming accounts (JK) :rofl: - TYVM ph4nt0m :h:(i just got to reading the news and annoucements) info is most appreciated!!! - just a curiousity...is it now detectable by current commercial AV software or is (or are) there particular sus files to look out for (like for example if your system have rpcnet.exe then definitely it is or can be accessed and monitored by Absolute - a legal tech biz providing anti-theft service living in the BIOS chipset pre-installed activated if owner opts to pay a subscription - currently unremoveable by flashing unless you unsolder and re-solder a clean BIOS chip not pre-installed by it - like in most sold alone mobos - they can geolocate u anywhere in the world and can disable your tech remotely..and who knows what else it can actually really do *wink* ).
 

Sharkando

Member
Downloaded
3.8 GB
Uploaded
5 GB
Ratio
1.32
Seedbonus
0
Upload Count
0 (0)
Member for 2 years
If you are using pirated software after activation kindly install a paid antivirus software to be safe always ensure you buy total security version
 
Top