
Cracked SQLi Dumper Tool Doubles as BitRAT Delivery Vehicle
A pirated copy of the SQLi Dumper v8.5 pentesting tool is being used to plant the BitRAT trojan on self-selecting victims who go looking for free security software. Shared packing and anti-analysis checks tie two lure files together, while a single isolated Russian-hosted IP and an unrelated third payload round out a thin but suggestive indicator set.
A pirated copy of a well-known penetration-testing utility is being used as bait to plant a commodity remote-access trojan on victim machines, according to indicators CTX Team has reviewed. Two Win32 executables in this cluster present themselves as a "cracked" release of SQLi Dumper v8.5, a SQL-injection scanning tool popular with penetration testers and opportunistic attackers alike, while sharing the same packing signature and a matching set of anti-analysis checks.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read