Incidents

Cybercriminals go shopping

It’s holiday time, and of course the bad guys know that shopping is a popular activity during this period, particularly in Europe and the US. And it’s in these regions that most people pay for their purchases either using credit cards, or e-payment systems like PayPal, WebMoney etc.

In order to target this data, cybercriminals create “universal” malicious programs, which will intercept all financial data, whether it related to credit cards, bank accounts, or e-payment systems.

A recent case shows this clearly: a botnet made up of several thousand machines was used to install Trojan.Win32.Vilsel.qhw on 972 victim machines, all of which are located in the US.

It seems likely that this botnet was rented specially in order to install this malware – a common practice in the cybercriminal world. There are plenty of places on the Internet which offer this “service”, as the screenshot below shows. In order to deliver the Trojan to 972 machines in the US, the bad guys would have had to pay around $100.

So where’s the profit in this? Well, the malware in question will intercept Internet transactions made using Internet Explorer and the new(ish) Chrome browser. That covers a huge percentage of Internet users, and because the malware targets a whole range of payment options, it won’t make any difference if payment is made by credit card or PayPal – confidential data will still get logged and then sent onwards to the bad guys.

Additionally, once it’s been run for the first time on the victim machine, this malware deletes its original file (to hide traces of infection); prevents access to Task Manager at system registry level, and also blocks Regedit, making it more difficult to manually check the system and identify and delete the malware.

According to VirusTotal, at the time of writing only 6/40 (15%) of antivirus vendors detected this threat, and a lot of the big names were among those missing.

Cybercriminals go shopping

Your email address will not be published. Required fields are marked *

 

Reports

Lyceum group reborn

According to older public researches, Lyceum conducted operations against organizations in the energy and telecommunications sectors across the Middle East. In 2021, we have been able to identify a new cluster of the group’s activity, focused on two entities in Tunisia.

GhostEmperor: From ProxyLogon to kernel mode

While investigating a recent rise of attacks against Exchange servers, we noticed a recurring cluster of activity that appeared in several distinct compromised networks. With a long-standing operation, high profile victims, advanced toolset and no affinity to a known threat actor, we decided to dub the cluster GhostEmperor.

APT trends report Q2 2021

This is our latest summary of advanced persistent threat (APT) activity, focusing on significant events that we observed during Q2 2021: attacks against Microsoft Exchange servers, APT29 and APT31 activities, targeting campaigns, etc.

Subscribe to our weekly e-mails

The hottest research right in your inbox