Executive Summary
RARSTONE is a Windows backdoor attributed to the Naikon group and shares key behaviors with PlugX—persistence, remote control, and credential theft. The malware communicates over encrypted HTTP/S channels. Immediate attention should focus on network traffic monitoring and limiting lateral movement privileges.
Enhanced Description
RARSTONE is a Windows‑based malware tool attributed to the Naikon threat actor, first reported by Aquino as exhibiting traits reminiscent of the PlugX backdoor family. Like PlugX, RARSTONE appears designed as a long‑lived foothold rather than immediate payload delivery. It establishes persistence through registry edits and scheduled tasks, allowing it to survive reboots and user sessions. The code base includes remote administration functions that expose shell access and file management capabilities, facilitating lateral movement within compromised networks. Early samples suggest the malware communicates with a command‑and‑control (C2) server using encrypted HTTP/S traffic, reducing detection risk by blending in with normal web traffic. Analysts also observe mechanisms for credential acquisition via keylogging or memory dumping, enabling attackers to expand their reach to privileged accounts.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the existence and attribution of RARSTONE is moderate based on published references. However, detailed technical information about its implementation and operational procedures remains sparse; further samples are required to confirm specific capabilities.
RARSTONE is malware used by the Naikon group that has some characteristics similar to PlugX. (Citation: Aquino RARSTONE)