
Dell SonicWALL Threats Research team discovered a RAT Trojan spreading through drive-by downloads from malicious links. The links were found hosting a malicious java applet under the guise of an online game. Once the applet is executed, it proceeds to download a Dark Comet RAT Trojan hosted on dropbox and executes it. Dark Comet is a remote administration tool but is often used for malicious purposes because of its Trojan like capabilities. In this instance, the RAT was used to capture the user's keystrokes along with relevant window information and upload it to a remote server.
Infection Cycle
The drive by download kicks in once the malicious page is visited. The security warning is shown as result of the Java applet being signed by a self-signed DSA certificate.

If an unwary user decides to allow the applet to run, it silently downloads and executes the RAT in background

The RAT is hosted on dropbox and the link to it is passed as a parameter to the Java applet as show below

Once executed the RAT Trojan performs the following activities:
![]()


SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News