Loading cryptocurrency prices...

New Chaos RAT Variant Targets Linux, Spreads via Fake Utilities

Chaos RAT Malware Targets Windows and Linux with Fake Network Tools and Cryptocurrency-Themed Attacks

  • A new version of Chaos RAT Malware is targeting both Windows and Linux systems.
  • The malware is spread through fake network tools and phishing emails, often disguised as Linux troubleshooting utilities.
  • Chaos RAT gives attackers remote access, file management, and control over infected devices.
  • Recent campaigns show connections with cryptocurrency mining activities and theft of wallet credentials.
  • Security flaws in the malware’s admin panel have been fixed as of May 2024.

A recent wave of cyber attacks is deploying an updated variant of the malware known as Chaos RAT, impacting both Windows and Linux operating systems. Researchers have found that attackers use deceptive network utility downloads and phishing emails to distribute the malware, particularly targeting Linux users.

- Advertisement -

Experts from Acronis revealed that Chaos RAT is an open-source remote access tool written in Go, supporting cross-platform deployment. Attackers often trick victims into downloading files disguised as helpful network tools, which in reality install the malware. Once on a system, Chaos RAT connects to an external server, enabling functions like launching remote command shells, managing files, collecting system information, and even shutting down or restarting machines. The latest observed version is 5.0.3, released May 31, 2024.

The Acronis research team stated, “Chaos RAT provides an administrative panel where users can build payloads, establish sessions, and control compromised machines.” They reported that Chaos RAT is used in cryptocurrency mining campaigns, with attacks distributing the malware through phishing links or attachments, and achieving persistence by modifying scheduled task files (such as “/etc/crontab” in Linux). The initial campaigns delivered both Chaos RAT and a separate cryptocurrency miner, showing that Chaos RAT was also used for gathering information about devices.

A with a sample uploaded to VirusTotal in January 2025 from India—titled “NetworkAnalyzer.tar.gz”—suggests attackers are disguising the malware as Linux troubleshooting tools to fool users. The management panel of Chaos RAT previously contained a high-severity vulnerability (CVE-2024-30850) that allowed command injection, as well as a cross-site scripting flaw (CVE-2024-31839). Both issues have now been fixed by the tool’s maintainer.

Researchers highlight that malicious actors use open-source malware like Chaos RAT because it can be quickly customized and makes it harder to determine who is behind attacks. They note that “using publicly available malware helps APT groups blend into the noise of everyday cybercrime,” complicating attribution attempts.

- Advertisement -

There is also evidence of ongoing campaigns attacking Trust Wallet users on desktop with fake wallets. These attacks are designed to collect browser credentials, extract data from crypto wallets, execute remote commands, and act as clipboard hijackers to steal sensitive information such as seed phrases and private keys. Details about this campaign were shared by Point Wild researcher Kedar S Pandit in a new report, noting the malware can monitor files, clipboard activity, and browser sessions to capture crypto asset details.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

US-China Trade Deal, CZ Pardon, Kyrgyzstan Launches Stablecoin

Scott Bessent, U.S. Treasury Secretary, announced progress on a trade deal framework between the...

North Korea Steals $2.84B in Crypto Amid Growing Cyber Threats

North Korea has stolen $2.84 billion in cryptocurrency during 2024.The country runs a large,...

US-China Trade Deal Progress Sparks Crypto Market Rally

The US and China have made significant progress on a trade deal framework.The deal...

AI-driven crypto payments via Coinbase protocol surge 4,300% in weekly growth – DL News

Use of the payment protocol x402, developed by Coinbase, among AI-powered agents surged sharply...

XRP Ledger’s Batch Amendment Nears Activation with NFT Trading Boost

The proposed XRP Ledger amendment called Batch (XLS-56) allows multiple transactions to be combined...
- Advertisement -

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...