Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware RARSTONE

RARSTONE

TLP:CLEAR
Family

AI Analysis

· 6 hours ago

Executive Summary

RARSTONE is a Windows backdoor attributed to the Naikon group and shares key behaviors with PlugX—persistence, remote control, and credential theft. The malware communicates over encrypted HTTP/S channels. Immediate attention should focus on network traffic monitoring and limiting lateral movement privileges.

Enhanced Description

RARSTONE is a Windows‑based malware tool attributed to the Naikon threat actor, first reported by Aquino as exhibiting traits reminiscent of the PlugX backdoor family. Like PlugX, RARSTONE appears designed as a long‑lived foothold rather than immediate payload delivery. It establishes persistence through registry edits and scheduled tasks, allowing it to survive reboots and user sessions. The code base includes remote administration functions that expose shell access and file management capabilities, facilitating lateral movement within compromised networks. Early samples suggest the malware communicates with a command‑and‑control (C2) server using encrypted HTTP/S traffic, reducing detection risk by blending in with normal web traffic. Analysts also observe mechanisms for credential acquisition via keylogging or memory dumping, enabling attackers to expand their reach to privileged accounts.

Key Capabilities

  • Persistent installation via registry and scheduled tasks
  • Encrypted HTTP/S command‑and‑control channel
  • Remote shell access and file system manipulation
  • Credential harvesting (memory dump/keylogging)

ATT&CK Techniques

T1059
T1071.001
T1105

Recommended Actions

  • Deploy network IDS to flag unusual outbound HTTPS connections to known malicious IPs.
  • Implement application whitelisting to block unauthorized executables.
  • Require least privilege for user accounts, especially those with admin rights.
  • Regularly patch Windows systems to mitigate exploitation of known vulnerabilities.

Suggested Tags

Naikon
PlugX‑similarity
Windows malware
Remote Access Trojan
Command-and-Control

Confidence Assessment

Confidence in the existence and attribution of RARSTONE is moderate based on published references. However, detailed technical information about its implementation and operational procedures remains sparse; further samples are required to confirm specific capabilities.

Description

RARSTONE is malware used by the Naikon group that has some characteristics similar to PlugX. (Citation: Aquino RARSTONE)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.