ToRat is an RAT (Remote Administration Tool) open-source project developed in Go. It can be found on GitHub. This malware is widely used in the hacking community because it offers the significant advantage of operating via a TOR onion service. There is no need to set up (or compromise) a server to host a C2, as it leverages the benefits of NAT traversal and anonymity provided by TOR (T1090.003). With a single command line, the implant is ready to be deployed and the server is already listening, thanks to the use of Docker containers!

This type of RAT offers significant advantages in terms of both simplicity and security. Its capabilities include: persistence, data destruction, command execution, file upload/download, internet connection testing, screen capture, file viewing, operating system information retrieval, and network scanning.

What exactly does TEHTRIS do to address this pressing threat?

Deobfuscation: The implant installed on the victim's machine is obfuscated using the Go Garbleutility, then packed T1027.002 with the UPXutility. It therefore goes unnoticed by many security systems, and retrieving its configuration statically is an extremely tedious task. To address this, the memory introspection capabilities of the TEHTRIS Sandbox allow for intercepting the malware's configuration directly in the process memory at the moment it is decrypted. This technique makes it possible to bypass unpacking and deobfuscation tasks by fully leveraging the mechanisms of the TEHTRIS Sandbox.

How is this useful for the analyst?: SOC analysts can thus access the configuration, which will allow them to effectively retrieve information specific to the ongoing attack: certificate, public key, address onion domain. Retrieving the configuration allows us to confirm the specific threat and avoid false positives.

Technical description (advanced users)

The malware is first obfuscated with go garble, then packed as shown in the following diagram:

The code responsible for the configuration in the implant is as follows; we are looking to retrieve the contents of the server structure:

package client

import (
"crypto/rsa"
"crypto/x509"
_ "embed" // used for embedding the cert
"encoding/pem"
"log"
)

const (
serverPort string = ":1337"
)

type server struct {
cert *x509.Certificate
pubKey *rsa.PublicKey
addr string
domain string
}

var s server

//go:embed cert.pem
var serverCert []byte

// initServer returns a struct with the cert, domain, pubkey, and address
// for dialing the source server's tor address
func initServer() {
serverBlock, _ := pem.Decode(serverCert)

cert, err := x509.ParseCertificate(serverBlock.Bytes)
if err != nil {
panic(err)
}

domain := cert.DNSNames[0]
log.Println("[initServer] Initialized server cert")

s = server{
cert: cert,
addr: domain + serverPort,
pubKey: cert.PublicKey.(*rsa.PublicKey),
domain: domain,
}
}

Go strings are equivalent to C structures as follows:

Garble obfuscates the Control Structure but not the structures. Using Docker to compile the code offers many advantages to the attacker, but in return, the result is highly deterministic. Since the expected architecture is x86_64, we can see the structure of Go strings in green, as expected for this architecture, with the pointer to the string and its length.

structstring{
const char *buffer;
size_t length;
}

Struct in memory

Pointers redirect to another memory area. This pattern is highly characteristic and, with a few optimizations—specifically heuristics based on the characteristics of memory areas—allows for the configuration to be recovered quickly.

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all