BeepRAT: China-Nexus Toolset Distributed via Telecom Utility
Score: 9/10

BeepRAT: China-Nexus Toolset Distributed via Telecom Utility

A customized variant of DcRAT named BeepRAT is being distributed via a Chinese phone number management utility, targeting telecommunications providers with an extensive C2 command framework.

Executive Summary

Rubrik Zero Labs has identified BeepRAT, a sophisticated China-nexus Remote Access Trojan (RAT) derived from the open-source DcRAT framework. The malware is distributed through a weaponized Chinese telecom management utility named 'HFY 匷码酁改.zip', which includes a SQLite database of over 500,000 Chinese mobile number prefixes. While no direct attribution is finalized, the infrastructure overlaps with clusters associated with Lotus Blossom, Silver Fox, and UNC5174.

The infection chain utilizes the Tiny C Compiler (TCC) to execute shellcode directly from memory, bypassing AMSI, ETW, and WLDP. BeepRAT establishes persistence via scheduled tasks and leverages a robust command-and-control (C2) framework supporting plugins, keylogging, and remote administration. The use of a hardcoded AES key containing the phrase 'QiAnXin is awesome' further cements its origin within the Chinese-speaking developer community.

This campaign poses a significant risk to the telecommunications sector, particularly organizations handling large scale mobile subscriber data. The malware's ability to evolve from LuaJIT-based to TCC-based loaders indicates an active development cycle focused on evading file-based detection mechanisms.

Key Details

Threat Name

BeepRAT

Affects

—

Adversary

Lotus Blossom Other Adversaries and Aliases: Silver Fox; UNC5174

Malware/Tools

BeepRAT, DcRAT, Chrysalis, ValleyRAT, VShell, Cobalt Strike

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance8
Enterprise Relevance8
Clarity & Structure10
Technical Depth9

Sources