Hackers hit with malware-ridden tools

A graphic displaying an ethical hacker

Security researchers have discovered a campaign where hackers themselves have become targets with malware-ridden tools offered online.

These tools enable an attacker to take full access of a victim's computer once unwittingly opened, according to Amit Serper from Cybereason.

Serper has been investigating a campaign that's been running for years and found that hackers were taking existing tools and injecting them with remote-access trojan malware.


The essential guide to cloud-based backup and disaster recovery

Support business continuity by building a holistic emergency plan


Some of the tools were designed to harvest data through via product key generators.

These were being repackaged and placed online, on forums and websites, to 'bait' other hackers in the hope that once in their systems, they would find backdoors into the networks they had hacked themselves.

The tools have been infected with njRat, a new strain of trojan which gives the attacker full access to the victim's computer, their files, passwords and even their webcam and microphone.

The njRat trojan is often spread through phishing emails and infected flash drives, but according to Serper, the malware has been embedded on to dormant or insecure websites. According to his research, these hackers have compromised several websites and are building new variations of the tools on a daily basis.

While hackers getting hacked may sound like a comeuppance, it's most likely fueling more criminal activity, according to Jake Moore, cyber security specialist at ESET. He suggests this could easily spread to a wider audience than just those intended.

"Once campaigns like this are released into the wild, they inevitably end up being used by other threat actors, which increases the number of targets on a wider scale," he said.

Ten of the most infamous ‘black hat’ hackers Inside the mind of a hacker How do you become an ethical hacker?

"Whilst the actors behind these campaigns may not be thinking about how moral such activities are, it highlights that even criminal hackers are susceptible to foul play and are vulnerable to impressive attacks."

Bobby Hellard

Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.

Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.