CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Freeze[.]rs Injector Weaponized for XWorm Malware Attacks

admin by admin
August 11, 2023
in Information Security
Freeze[.]rs Injector Weaponized for XWorm Malware Attacks


Aug 10, 2023THNMalware / Cyber Threat

Malicious actors are using a legitimate Rust-based injector called Freeze[.]rs to deploy a commodity malware called XWorm in victim environments.

The novel attack chain, detected by Fortinet FortiGuard Labs on July 13, 2023, is initiated via a phishing email containing a booby-trapped PDF file. It has also been used to introduce Remcos RAT by means of a crypter called SYK Crypter, which was first documented by Morphisec in May 2022.

“This file redirects to an HTML file and utilizes the ‘search-ms’ protocol to access an LNK file on a remote server,” security researcher Cara Lin said. “Upon clicking the LNK file, a PowerShell script executes Freeze[.]rs and SYK Crypter for further offensive actions.”

Freeze[.]rs, released on May 4, 2023, is a open-source red teaming tool from Optiv that functions as a payload creation tool used for circumventing security solutions and executing shellcode in a stealthy manner.

Cybersecurity

“Freeze[.]rs utilizes multiple techniques to not only remove Userland EDR hooks, but to also execute shellcode in such a way that it circumvents other endpoint monitoring controls,” according to a description shared on GitHub.

SYK Crypter, on the other hand, is a tool employed to distributed a wide variety of malware families such as AsyncRAT, NanoCore RAT, njRAT, QuasarRAT, RedLine Stealer, and Warzone RAT (aka Ave Maria). It’s retrieved from the Discord content delivery network (CDN) by means of a .NET loader attached to emails that masquerades as benign purchase orders.

“This attack chain delivers a crypter that is persistent, features multiple layers of obfuscation, and uses polymorphism to maintain its ability to avoid detection by security solutions,” Morphisec researcher Hido Cohen explained.

XWorm Malware Attacks

It’s worth noting that the abuse of the “search-ms” URI protocol handler was recently highlighted by Trellix, which unearthed infection sequences bearing HTML or PDF attachments to run searches on an attacker-controlled server and list malicious files in the Windows File Explorer as if they are local search results.

Cybersecurity

The findings from Fortinet are no different in that the files are camouflaged as PDF files but are actually LNK files that execute a PowerShell script to launch the Rust-based injector, while displaying a decoy PDF document.

In the final stage, the injected shellcode is decrypted to execute the XWorm remote access trojan and harvest sensitive data, such as machine information, screenshots, and keystrokes, and remotely control the compromised device.

The fact that a three-month-old program is already being weaponized in attacks symbolizes the rapid adoption of offensive tools by malicious actors to meet their goals.

That’s not all. The PowerShell script, besides loading the injector, is configured to run another executable, which functions as a dropper by contacting a remote server to fetch the SYK Crypter containing the encrypted Remcos RAT malware.

“The combination of XWorm and Remcos creates a formidable trojan with an array of malicious functionalities,” Lin said. “The C2 server’s traffic report […] reveals Europe and North America as the primary targets of this malicious campaign.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

AWS Security Profile: Get to know the AWS Identity Solutions team

Next Post

Researchers Uncover Years-Long Cyber Espionage on Foreign Embassies in Belarus

Related Posts

Information Security

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

by admin
September 30, 2023
Information Security

Manage AWS Security Hub using CloudFormation

by admin
September 30, 2023
Information Security

Is that how it works? Hacking and scamming in popular TV shows

by admin
September 30, 2023
Information Security

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

by admin
September 29, 2023
Information Security

Get the full benefits of IMDSv2 and disable IMDSv1 across your AWS infrastructure

by admin
September 29, 2023
Next Post

Researchers Uncover Years-Long Cyber Espionage on Foreign Embassies in Belarus

Recommended

InnovationBreakthrough Chapter V Innovation Risk Management ~ Future of CIO

September 30, 2023

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

September 30, 2023

Manage AWS Security Hub using CloudFormation

September 30, 2023

Is that how it works? Hacking and scamming in popular TV shows

September 30, 2023

InnovationBreakthrough Introduction:Chapter 3 Business Model Innovation ~ Future of CIO

September 29, 2023

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

September 29, 2023

© CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 CIO News Hubb All rights reserved.