A new advertised malware, BitRat, offered at 20 dollars on Darknet forums, has most recently used hijacked information from the IT infrastructure of a Columbian bank. The threat actors managed to gain access to customer data including: Cedula numbers (Columbian national ID), email addresses, phone numbers, customer names, payment records, salary, and address. The threat group then used the stolen data to craft emails that used the breached data as a lure to trick victims into downloading the malware. The malware has the capabilities for:
- Data exfiltration
- Execution of payloads with bypasses.
- DDoS
- Keylogging
- Webcam and microphone recording
- Credential theft
- Monero mining
- Running tasks for process, file, software, etc.