Executive Summary
Rubrik Zero Labs has identified BeepRAT, a sophisticated China-nexus Remote Access Trojan (RAT) derived from the open-source DcRAT framework. The malware is distributed through a weaponized Chinese telecom management utility named 'HFY 匷码酁改.zip', which includes a SQLite database of over 500,000 Chinese mobile number prefixes. While no direct attribution is finalized, the infrastructure overlaps with clusters associated with Lotus Blossom, Silver Fox, and UNC5174.
The infection chain utilizes the Tiny C Compiler (TCC) to execute shellcode directly from memory, bypassing AMSI, ETW, and WLDP. BeepRAT establishes persistence via scheduled tasks and leverages a robust command-and-control (C2) framework supporting plugins, keylogging, and remote administration. The use of a hardcoded AES key containing the phrase 'QiAnXin is awesome' further cements its origin within the Chinese-speaking developer community.
This campaign poses a significant risk to the telecommunications sector, particularly organizations handling large scale mobile subscriber data. The malware's ability to evolve from LuaJIT-based to TCC-based loaders indicates an active development cycle focused on evading file-based detection mechanisms.
