SteelFox Leverages Signed Windows Drivers to Attack Kernel


This week, the SonicWall Capture Labs threat research team investigated a sample of SteelFox malware.

This is bundled with “software activators” for JetBrains and Foxit PDF readers. During installation, they run as a service and use vulnerable signed Windows drivers to exploit and attack the kernel. Secondarily, cryptominers such as XMRig are run in memory via AppInfo, as well as network communications. The sample is detected as an executable without a packer or protector; however, the file entropy shows that it is, in fact, packed.

Read more…
Source: SonicWall


Sign up for our Newsletter


Related:

  • The story of the year: remote work

    December 10, 2020

    The coronavirus pandemic has caused sudden, sweeping change around the world. The necessary social distancing measures are having an impact on all of us. One large part of society that has been affected by these measures more than others is the employed. While direct customer facing businesses like restaurants and retailers have had to change ...

  • A Security Guide to IoT-Cloud Convergence

    December 10, 2020

    The internet of things (IoT) has risen as one solution to the demands that have emerged because of the worldwide pandemic. The IoT, with its key characteristic of minimizing human interaction in performing a myriad of functions, seems a perfect fit in a world of remote setups and social distancing. But it is thanks to ...

  • Chinese APT suspected of supply chain attack on Mongolian government agencies

    December 10, 2020

    A Chinese state-sponsored hacking group, also known as an APT, is suspected of having breached a Mongolian software company and compromised a chat app used by hundreds of Mongolian government agencies. The attack is believed to have taken place earlier this year, in June, according to a report published today by Slovak security firm ESET. The hackers ...

  • European Medicines Agency says it has been targeted by cyber attack

    December 9, 2020

    In a short statement published on its website, the agency said: “EMA has been the subject of a cyberattack. The agency has swiftly launched a full investigation, in close cooperation with law enforcement and other relevant entities. “EMA cannot provide additional details whilst the investigation is ongoing. Further information will be made available in due course,” ...

  • FireEye reveals that it was hacked by a nation state APT group

    December 9, 2020

    Leading cybersecurity company FireEye disclosed today that it was hacked by a threat actor showing all the signs of a state-sponsored hacking group. The attackers were able to steal Red Team assessment tools FireEye uses to test customers’ security and designed to mimic tools used by many cyber threat actors. Read more… Source: Bleeping Computer  

  • Foxconn electronics giant hit by ransomware, $34 million ransom

    December 9, 2020

    Foxconn electronics giant suffered a ransomware attack at a Mexican facility over the Thanksgiving weekend, where attackers stole unencrypted files before encrypting devices. Foxconn is the largest electronics manufacturing company globally, with recorded revenue of $172 billion in 2019 and over 800,000 employees worldwide. Foxconn subsidiaries include Sharp Corporation, Innolux, FIH Mobile, and Belkin. BleepingComputer has been ...