Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New ResolverRAT Malware: A Stealthy Threat to Global Pharma and Healthcare Organizations



A new remote access trojan (RAT) called 'ResolverRAT' is being used against organizations globally, with the malware targeting the healthcare and pharmaceutical sectors. The discovery of this highly sophisticated malware highlights the evolving nature of cyber threats and emphasizes the need for organizations to stay vigilant in protecting themselves against such threats.

  • New Resolver RAT malware has been discovered, posing a significant threat to global pharmaceutical and healthcare organizations.
  • The malware is being used in phishing email campaigns targeting countries with languages matching the attackers' country of origin.
  • ResolverRAT uses reflective DLL loading to inject itself into memory, making it difficult for traditional security monitoring to detect.
  • The malware uses complex state machines and obfuscated code to evade detection by sandbox and analysis tools.
  • ResolverRAT adds XOR-obfuscated keys to the Windows Registry and filesystem locations to secure persistence.
  • The malware features command-and-control functionality with irregular beaconing patterns to evade detection.
  • ResolverRAT includes a chunking mechanism for large data transfers and optimal error handling mechanisms.
  • Morphisec observed phishing attacks in multiple languages, indicating a global operational scope.
  • The discovery highlights the evolving nature of cyber threats and the importance of staying vigilant.



  • New ResolverRAT malware has been discovered, posing a significant threat to global pharmaceutical and healthcare organizations. This highly sophisticated remote access trojan (RAT) is being used in phishing email campaigns targeting countries with languages that match the attackers' country of origin.

    According to Morphisec, a leading cybersecurity firm, the phishing emails contain a link to download what appears to be a legitimate executable file called 'hpreader.exe'. However, this file is actually used as leverage to inject ResolverRAT into memory using reflective DLL loading. This method allows the malware to operate entirely in memory, making it difficult for traditional security monitoring focused on Win32 API and file system operations to detect.

    ResolverRAT's capabilities are further enhanced by its use of complex state machines to obfuscate control flow and make static analysis extremely challenging. The malware also uses misleading and redundant code/operations to complicate analysis, even in the presence of debugging tools. This stealthy approach has allowed ResolverRAT to evade detection by sandbox and analysis tools, making it a significant threat to global organizations.

    To secure persistence, ResolverRAT adds XOR-obfuscated keys on up to 20 locations at the Windows Registry. Additionally, it also adds itself to filesystem locations such as 'Startup', 'Program Files', and 'LocalAppData'. This ensures that the malware remains persistent even after the initial infection has been removed.

    ResolverRAT's command-and-control (C2) functionality is also noteworthy. The malware attempts to connect at scheduled callbacks at random intervals, using irregular beaconing patterns to evade detection. Every command sent by the operators is handled in a dedicated thread, enabling parallel task execution while ensuring failed commands do not crash the malware.

    Furthermore, ResolverRAT features a chunking mechanism for large data transfers, splitting files larger than 1MB into 16KB chunks to evade detection. The malware also includes optimal error handling and data recovery mechanisms, resuming transfers from the last successful chunk.

    Morphisec observed phishing attacks in Italian, Czech, Hindi, Turkish, Portuguese, and Indonesian languages, indicating that the malware has a global operational scope that could be expanded to include more countries.

    The discovery of ResolverRAT highlights the evolving nature of cyber threats and the importance of staying vigilant. As cybersecurity measures continue to advance, attackers are adapting their tactics to remain one step ahead. It is essential for organizations to stay informed and take proactive steps to protect themselves against such threats.

    In light of this latest development, it is crucial to review existing security protocols and consider additional measures to mitigate the risks associated with ResolverRAT.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-ResolverRAT-Malware-A-Stealthy-Threat-to-Global-Pharma-and-Healthcare-Organizations-ehn.shtml

  • https://www.bleepingcomputer.com/news/security/new-resolverrat-malware-targets-pharma-and-healthcare-orgs-worldwide/


  • Published: Mon Apr 14 13:11:33 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us