Posts

DuckTail

Image
  DUCKTAIL, a financially motivated malware variant, is crafted by Threat Actors (TAs) based in Vietnam and strategically targets individuals and businesses utilizing Social Media Business/Ads platforms. Since the latter part of 2021, these threat actors have been actively engaged in developing and disseminating malware associated with the DUCKTAIL operation. This malicious software is intricately designed to extract browser cookies, exploiting active social media sessions to pilfer sensitive information from the victim's social media account. The ultimate objective of the malware operation is to seize control of Social Media Business accounts endowed with substantial access privileges. The threat actors leverage this acquired access to orchestrate advertisements, aiming for financial gains. Target OS  Windows 7 to Windows 11 , both 32-64 bit, including Server editions. Infection Vector In this campaign, a new tactic emerges as the threat actor employs LNK (shortcut) files wit...

Qakbot

Image
  QakBot, also known as Qbot, is a sophisticated and notorious banking trojan and information-stealing malware that has been active since around 2008. Over the years, it has evolved and gained new capabilities, making it a potent threat in the realm of cybercrime. QakBot primarily targets Windows operating systems and is designed to compromise sensitive information, particularly financial data and login credentials. Target OS  Windows XP to Windows 11 , both 32-64 bit, including Server editions.  Infection Vector   The targets reported receiving emails claiming to be from an IRS employee in latest campaign identified by Microsoft on 11 Dec 2023 on Twitter , which included a PDF attachment.The PDF contained a web link that triggered the download of a digitally signed Windows Installer (.msi) file. When the recipients executed the MSI file, it initiated the QakBot malware through the execution of an embedded DLL using the 'hvsi' export. This technique allows the malwa...

Lumma Stealer

Image
  LummaStealer is a Malware-as-a-Service (MaaS) available on the dark web, reflecting a shift in the cyber threat landscape. Unlike traditional methods, this platform enables aspiring threat actors to access sophisticated malware without intricate technical skills. The malware marketplace has evolved, emphasizing user-friendly experiences, ease of use, and ongoing development to outsmart antivirus systems. With LummaStealer and similar services, emerging cybercriminals receive not only professionally crafted malware but also guaranteed troubleshooting and customer support, significantly lowering the entry barrier for malicious activities. This trend highlights the commercialization and accessibility of cyber threats, potentially empowering a broader range of individuals in the realm of cybercrime. Target OS     Windows 7 to Windows 11 , both 32-64 bit, including Server editions. Infection Vector Lumma Stealer has been identified employing various distribution tactics...

RedLine Stealer

Image
  RedLine Stealer, initially identified in March 2020, stands out as a prominent malware known for its theft capabilities. Positioned as a sought-after commodity in the cyber underworld, it is marketed as Malware-as-a-Service (MaaS). The appeal of RedLine Stealer lies in its widespread availability and adaptability. This malicious software is engineered to extract sensitive data from compromised systems. Its primary focus is on pilfering information from web browsers, including but not limited to saved login credentials and payment card details. Beyond this, RedLine Stealer conducts a comprehensive sweep of the target system, gathering data such as usernames, hardware configurations, installed software (both general and security-oriented), presence of VPN clients, network configurations, and even data related to cryptocurrencies. Subsequently, the pilfered information is discreetly transmitted to the malicious actors orchestrating the attack. Target OS  Windows XP to Windows ...

Remcos RAT

Image
      Remcos RAT, initially developed as a legitimate tool for remote computer control, has gained notoriety as a malware family due to its exploitation by hackers for unauthorized access to victims' devices since its inception on July 21, 2016. Despite its origins as professional software, it has been repurposed for malicious activities. It is available for purchase on the internet, making it a commercial product in the realm of cyber threats.   Target OS  Windows XP to Windows 11 , both 32-64 bit, including Server editions. Infection Vector Remcos is frequently distributed through phishing attacks. It is often concealed within a deceptive ZIP file, pretending to be a PDF document related to an invoice or order. Another method involves the use of Microsoft Office documents with embedded malicious macros. When opened, these documents unpack and execute the Remcos malware, showcasing the versatility of tactics employed by attackers in disseminating this threat. ...