Russian Businesses Under Siege: Horns&Hooves Malware Campaign Spreads Dangerous RATs Through Deceptive Emails


Russian Businesses Under Siege: Horns&Hooves Malware Campaign Exposed

A sophisticated cyber attack campaign dubbed Horns&Hooves has compromised over 1,000 Russian businesses and individuals since March 2023. The operation deploys advanced trojans including NetSupport RAT and BurnsRAT to distribute dangerous stealer malware variants Rhadamanthys and Meduza.

The attackers utilize deceptive ZIP archives containing JScript files, masquerading as legitimate business communications. To increase success rates, the campaign employs decoy documents and HTML Application (HTA) files that leverage Windows utilities like curl and BITSAdmin for malware deployment. The Remote Manipulator System (RMS) is implemented for unauthorized system control.

The campaign has undergone several evolutionary phases, including:
– Initial HTA-based deployment
– Next.js library impersonation
– NSIS installer variant
– Direct JavaScript implementation

Security researchers have identified potential links to the notorious threat actor TA569, also known as Gold Prelude/Mustard Tempest/Purple Vallhund. This group is previously associated with SocGholish malware and providing entry points for ransomware attacks such as WastedLocker. Successful breaches can lead to extensive data theft, system encryption, and severe infrastructure damage.

Share This Article