Fake National Health Service Site Delivers StreamRat on Android and XWorm on Windows

Summary
CERT-AGID analyzed a fake Italian National Health Service site that serves StreamRat to Android devices and an obfuscated PowerShell loader leading to XWorm on Windows. StreamRat can receive targets and HTML overlays dynamically from its server.
Key points
- The fake site uses the National Health Service name and appearance as a lure and serves different malware based on the visitor’s browser User-Agent.
- On Android, SSN.apk decodes and installs a second APK containing StreamRat, which prompts users to enable Accessibility services.
- StreamRat can read and control the device interface, capture screens, run commands, and display attacker-supplied HTML overlays to collect entered information.
- StreamRat reports the foreground app to its server, which can select targets and supply overlays dynamically without requiring the malware to be redistributed.
- On Windows, SSN Windows.bat launches hidden PowerShell, retrieves a file disguised as 2.jpg, and loads a .NET assembly in memory before the chain delivers XWorm.
- The Android and Windows branches use different malware but both aim to provide attackers with extensive remote access to compromised devices.
- CERT-AGID published indicators of compromise for the campaign.
Article Details
- Attack Vectors
- A fake Servizio Sanitario Nazionale page selects a download based on the visitor's browser User-Agent: SSN.apk for Android or SSN Windows.bat for Windows.
- The Android APK decodes and installs a second APK containing StreamRat. The app presents a false update request and asks the user to enable Android Accessibility services.
- StreamRat can receive commands over WebSocket on TLS, control the device interface, capture its screen, and display remotely supplied HTML overlays to collect information entered by the user.
- The Windows BAT file launches a hidden PowerShell instance. It retrieves a file named 2.jpg, decodes a Base64-encoded .NET executable from its contents, loads it in memory, and ultimately leads to XWorm execution.
- Defensive Notes
- The purported SSN app's request for Android Accessibility access is a significant warning sign: the analyzed malware uses that access to observe and control the interface.
- The SSN branding is an installation lure, not evidence that subsequent malicious activity targets only healthcare services; the Android malware can receive overlay targets dynamically.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe Android APK stores a second APK XOR-encoded in an asset; the Windows download contains a Base64-encoded .NET executable between markers.T1036.008 · Masquerade File TypeThe Windows-stage file is named 2.jpg but is processed as text containing an encoded executable, not as an image.T1056.002 · GUI Input CaptureStreamRat can place attacker-supplied HTML pages over apps to collect information the user enters.T1059.001 · PowerShellSSN Windows.bat launches a hidden PowerShell instance that retrieves and loads the next-stage executable.T1071.001 · Web ProtocolsThe Android payload communicates with its command server using WebSocket on TLS.T1105 · Ingress Tool TransferThe Windows loader attempts to retrieve the next-stage file, 2.jpg, from one of several URLs.T1113 · Screen CaptureThe analyzed StreamRat sample can capture the compromised Android device's screen.T1140 · Deobfuscate/Decode Files or InformationThe Android APK decodes its embedded APK using an XOR key, while the Windows loader decodes the Base64 executable before loading it.T1204.002 · Malicious FileThe fake SSN page relies on users downloading and running an Android APK or Windows BAT file.
Malware
StreamRatDa un dispositivo Android viene proposto il download di SSN.apk, che porta all’installazione del malware StreamRat.XWormVisitando la stessa infrastruttura da Windows viene invece scaricato SSN Windows.bat, un loader offuscato che avvia una catena PowerShell e porta infine all’esecuzione di XWorm, un Remote Access Trojan per Windows.
Products
AndroidIl CERT-AGID ha analizzato una campagna malevola che sfrutta il nome e l’identità visiva del Servizio Sanitario Nazionale per distribuire malware sia su dispositivi Android sia su sistemi Windows.PowerShellVisitando la stessa infrastruttura da Windows viene invece scaricato SSN Windows.bat, un loader offuscato che avvia una catena PowerShell e porta infine all’esecuzione di XWorm, un Remote Access Trojan per Windows.WindowsIl CERT-AGID ha analizzato una campagna malevola che sfrutta il nome e l’identità visiva del Servizio Sanitario Nazionale per distribuire malware sia su dispositivi Android sia su sistemi Windows.