Old Cardinal RAT Malware Resurrects Through Series Of Updates

- Advertisement -

Israeli tech companies, beware: This malware family is back after two years in hiding.

A type of malware family not seen since 2017 has resurfaced and is targeting FinTech and cryptocurrency companies in Israel, according to a March 19 blog post from cybersecurity watchdog Unit 42.

The previous version of the malware family, dubbed Cardinal RAT, employed the Carp Downloader, which uses “malicious macros in Microsoft Excel documents to compile embedded C# (C Sharp) Programming Language source code into an executable that in turn is run to deploy the Cardinal RAT malware.”

According to Unit 42, the new version of the Cardinal RAT malware comes with updates and modifications that “evade detection and hinder analysis.” This version of Cardinal RAT uses a variety of obfuscation techniques, including hiding malicious code in in a bitmap file. Once the victim opens the file, the malware is decrypted and begins to infect the victim’s computer.

- Advertisement -

Unit 42 confirmed the updated version of Cardinal RAT infects the victim’s computer by collecting victim information, updating settings, acting as a reverse proxy, executing a command, uninstalling itself, recovering passwords, downloading and executing new files, keylogging, capturing screenshots, and cleaning cookies from browsers.

According to The Next Web, in addition to nine reports from Israel of Cardinal RAT Malware attacks, there have been two in the US and one in both Japan and Austria. To protect one’s personal data from malware attacks, Unit 42 suggests that individuals and companies beef up their spam filters and parental controls to “restrict use of scripting languages by malware” and not open or even allow “inbound e-mails with LNK file as attachments [or] … e-mails from external sources where the documents contain macros.”

Although the Cardinal RAT malware was silent for two years, there have been quite a few malware attacks targeting the personal data of people and companies. Just last month, cybersecurity firm ESET announced it discovered malware created to steal crypto wallet addresses and personal keys infecting the Google Play store.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest Cardinal RAT, Carp Downloader or other Ethereum ecosystem news.



Previous Articles:

- Advertisement -

Latest News

OpenClaw Hype vs. Reality: AI Agent Rise Brings Serious Security Risks

The open-source AI agent framework OpenClaw amassed roughly 147,000 GitHub stars within weeks, sparking...

Bitcoin Tanks to $74.5K Amid $1.3B ETF Exodus

Bitcoin’s price fell to a year-to-date low of $74,555, marking a 40% drawdown from...

SpaceX Merges with xAI In $1.25 Trillion Vertical Integration Deal

SpaceX has officially acquired xAI, forming a single entity valued at $1.25 trillion.Elon Musk...

Hedera Developer Day Denver Feb 2026

The Hedera network will introduce a high-volume throttle system for entity creation (HIP-1313) alongside...

Bitcoin Dips Below MicroStrategy’s $76k Cost Basis

Strategy's massive Bitcoin holdings, purchased at a lifetime average of $76,052, are now worth...
- Advertisement -

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!