NonEuclid: A Sophisticated Remote Access Trojan (RAT) Blending Evasion and Ransomware Capabilities

Cybersecurity experts have uncovered a new remote access trojan (RAT) named NonEuclid, which enables attackers to remotely control compromised Windows systems.

“NonEuclid, developed in C#, is a highly advanced malware that provides unauthorized remote access and employs sophisticated evasion techniques,” Cyfirma stated in a technical analysis published last week.

The RAT leverages a range of methods, including antivirus bypassing, privilege escalation, anti-detection mechanisms, and ransomware encryption targeting critical files.

First detected in underground forums in late November 2024, NonEuclid has been actively advertised as a crimeware solution. Discussions and tutorials about the malware have also surfaced on platforms like Discord and YouTube, signaling a deliberate effort to promote and distribute it.

Read More: Cyberattackers Seize Control of 16 Chrome Extensions, 600,000 Users Data at Risk

Core Functionality

NonEuclid initiates with a client application setup, followed by multiple anti-detection checks. Once these are completed, it establishes a TCP socket for communication with a designated IP address and port. The malware configures exclusions in Microsoft Defender Antivirus to evade detection and monitors processes such as “taskmgr.exe,” “processhacker.exe,” and “procexp.exe,” which are commonly used for process management and analysis.

“NonEuclid employs Windows API calls, such as CreateToolhelp32Snapshot, Process32First, and Process32Next, to enumerate active processes and match their names against specific targets,” Cyfirma noted. Based on the AntiProcessMode setting, it can either terminate these processes or cause the client application to exit.

Anti-Analysis and Evasion Techniques

The malware incorporates several anti-analysis strategies, including checks to detect virtual machines or sandboxed environments, terminating itself if such conditions are identified. It also bypasses the Windows Antimalware Scan Interface (AMSI) to avoid being flagged by security systems.

Persistence and Ransomware Features

NonEuclid maintains persistence through scheduled tasks and modifications to the Windows Registry. It also attempts to elevate privileges by bypassing User Account Control (UAC) protections to execute commands. Notably, it includes a ransomware component, encrypting files with extensions like .CSV, .TXT, and .PHP and appending them with the extension .NonEuclid.

Increasing Threat Sophistication

“NonEuclid represents the growing sophistication of modern malware, blending advanced stealth capabilities, anti-detection mechanisms, and ransomware functionalities,” Cyfirma explained. Its promotion across underground forums, Discord, and tutorial platforms underscores its appeal to cybercriminals and highlights the challenges in countering such threats.

With features like privilege escalation, AMSI bypass, and process termination, NonEuclid demonstrates a high level of adaptability in evading security defenses.

Zarnab Latif

Zarnab Latif is a versatile technical writer with a passion for demystifying the complexities of Artificial Intelligence (AI). She excels at creating clear, concise and user-friendly content that helps developers, engineers, and non-technical stakeholders understand and effectively utilize AI technologies.

Recent Posts

Microsoft Brings Phi-4 Model to Hugging Face Platform

Microsoft has unveiled its latest language model, Phi-4, on Hugging Face, making it available under…

18 hours ago

AI start-up Anthropic Eyes $2 Billion, $60 Billion Valuation in Latest Funding Round: Report

AI start-up Anthropic is on the edge of securing an additional $2 billion in funding,…

1 day ago

AWS Launches New Asia Pacific (Thailand) Region with $5 Billion Investment

Amazon Web Services (AWS) has officially launched a new cloud computing region in Thailand, marking…

2 days ago

Amazon Web Services (AWS) Invests $11 Billion in Georgia to Fuel AI Growth

AWS has announced a major $11 billion investment in Georgia to expand its cloud computing…

2 days ago

Microsoft Powers Up India with Massive $3 Billion AI Investment

Microsoft plans to invest approximately $3 billion to enhance its AI and Azure cloud-computing capabilities…

3 days ago

HERE and Amazon Forge 10-Year $1 billion Partnership to Enhance ADAS and SDVs

Amazon (AMZN) and mapping technology company HERE have entered a 10-year, $1 billion partnership to…

3 days ago