VMDetector-Based Loader Abuses Steganography to Deliver Infostealers


Recently, the SonicWall Capture Labs threat research team has identified various malware strains being distributed through a custom VMDetector Loader. This loader is typically delivered to the victim’s system via image files embedded with steganography. The primary payloads observed include popular malware families such as Remcos, VIPKeyLogger, AveMariaRAT, DCRAT, FormBook, and others.

Attackers send an email with an archive file that includes either JavaScript, VBScript, or HTA content. The embedded scripts employ basic obfuscation through string replacement and base64 encoding, making them appear benign while evading straightforward detection.

Read more…
Source: Sonicwall


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • CISA Releases Twelve Industrial Control Systems Advisories

    August 10, 2023

    CISA released twelve Industrial Control Systems (ICS) advisories on August 10, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-23-222-01 Siemens Solid Edge, JT2Go and Teamcenter Visualization ICSA-23-222-02 Siemens Parasolid Installer ICSA-23-222-03 Siemens JT Open, JT Utilities, and Parasolid Read more… Source: U.S. Cybersecurity and Infrastructure Security Agency  

  • Common TTPs of attacks against industrial organizations

    August 10, 2023

    In 2022 Kaspersky investigated a series of attacks against industrial organizations in Eastern Europe. In the campaigns, the attackers aimed to establish a permanent channel for data exfiltration, including data stored on air-gapped systems. Based on similarities found between these campaigns and previously researched campaigns (e.g., ExCone, DexCone), including the use of FourteenHi variants, specific TTPs ...

  • Germany says Charming Kitten hackers target Iran dissidents

    August 10, 2023

    Germany’s Federal Office for the Protection of the Constitution (BfV) on Thursday warned critics of the Iranian leadership living in Germany that they might be targeted by hackers. The agency said the Charming Kitten online espionage group works by building trust with victims to the extent that they expose data on themselves, and any online ...

  • An overview of the new Rhysida ransomware targeting the Healthcare sector

    August 9, 2023

    On August 4, 2023, the HHS’ Health Sector Cybersecurity Coordination Center (HC3) released a security alert about a relatively new ransomware called Rhysida (detected as Ransom.PS1.RHYSIDA.SM), which has been active since May 2023. In this blog entry, Trend Micro reaseachers will provide details on Rhysida, including its targets and what they know about its infection ...

  • Attackers Distribute Malware via Freeze.rs And SYK Crypter

    August 9, 2023

    FortiGuard Labs recently detected a new injector written in Rust—one of the fastest-growing programming languages—to inject shellcode and introduce XWorm into a victim’s environment. While Rust is relatively uncommon in malware development, several campaigns have adopted this language since 2019, including Buer loader, Hive, and RansomExx. FortiGuard Labs analysis also revealed a significant increase in injector ...

  • Personal data of at least 26,212 people accessed in ransomware attack, Dallas tells state

    August 9, 2023

    Computer hackers accessed the personal information of at least 26,212 Texans in the recent ransomware attack on the city of Dallas, according to an official disclosure made public Monday on the Texas attorney general’s web site, three months after the breach. The city’s notice to the attorney general’s office says the data breach included names, addresses, ...