ResolverRAT Malware
Summary
Cybersecurity researchers have identified a sophisticated remote access trojan named ResolverRAT, which is actively being used in attacks targeting the healthcare and pharmaceutical sectors. Emails are written in the native languages of the targeted regions—Hindi, Italian, Czech, Turkish, Portuguese, and Indonesian—highlighting the attackers intent to increase infection success through region-specific tailoring. ResolverRAT uses a multi-stage bootstrapping process with redundant persistence mechanisms, embedding itself in various locations on the Windows file system and Registry. It cleverly splits large data files into 16 KB chunks, reducing the risk of detection by network monitoring tools. Its design reflects a sophisticated understanding of modern cybersecurity defenses, making it a formidable threat to targeted industries and a high-priority concern for defenders.