SharpRhino RAT
Summary
This malware facilitates initial infection, privilege escalation on compromised systems, execution of PowerShell commands and ultimately the deployment of ransomware. Among its notable victims are Austal USA, a U.S. Navy contractor, Japanese optics giant Hoya, Integris Health, and the Fred Hutch Cancer Center, highlighting the groups disregard for ethical boundaries. SharpRhino is distributed as a digitally signed 32-bit installer (ipscan-3.9.1-setup.exe) that includes a self-extracting, password-protected 7z archive containing additional files necessary for the infection process. Upon installation, the software alters the Windows registry for persistence and creates a shortcut to Microsoft.AnyKey.exe, a Microsoft Visual Studio binary that is misused in this context. To weaken the impact of ransomware attacks, implement a robust backup plan, practice network segmentation, and keep all software up to date to minimize opportunities for privilege escalation and lateral movement.