The cybersecurity researchers at Trend Micro recently identified that the Blackcat Ransomware (aka ALPHV) actors are using malvertising tricks to spread fake WinSCP installers via Targeted Attack Detection (TAD) service.
In these advertising campaigns, the threat actors lured their victims by using the cloned web pages of legitimate organizations.
Google Ads boosts sales by targeting audiences with tailored ads, driving traffic for businesses.
While in this case, threat actors make use of these platforms to launch malvertising campaigns that exploit keyword hijacking to trap search engine users with malicious ads and distribute malware stealthily.
Delaying intervention would have severely impacted the enterprise, considering the threat actors’ acquisition of domain admin privileges and establishment of backdoors, leading to significant consequences.
Upon searching “WinSCP Download” on Bing, the user encounters a deceptive ad promoting the application positioned above the organic search results. Clicking the ad redirects to a suspicious website featuring a tutorial on automated file transfers via WinSCP.
After landing on the initial page, the user is sent to a cloned WinSCP download site:-
Clicking “Download” initiates an ISO file download from an infected WordPress page:-
While the final payload URL was later switched to the file-sharing service 4 shared by the malicious actor.
Once the victim clicks, they get an ISO file with “setup.exe” and “msi.dll” – the former tempts the user to open it, while the latter acts as the triggered malware dropper.
Upon executing setup.exe, it triggers msi.dll, extracting a Python folder from the DLL RCDATA section, and also functioning as the genuine WinSCP installer for installation.
The process includes installing a trojanized python310.dll and establishing persistence through a run key named “Python” with the following value:-
A modified obfuscated python310.dll file is loaded on successful execution of pythonw.exe. The python310.dll file includes a Cobalt Strike beacon, which establishes a connection to a C2 server.
With Cobalt Strike operational, executing scripts, retrieving tools for lateral movement, and intensifying the compromise becomes effortless.
Here below we have mentioned all the tools that are used by the Blackcat Ransomware (aka ALPHV):-
Apart from this, ALPHV also employed SpyBoy “Terminator,” it’s a tool that disables EDR and antivirus solutions.
Here below we have mentioned all the recommendations offered by the researchers:-
“AI-based email security measures Protect your business From Email Threats!” – .
Since 2013, the advanced persistent threat (APT) known as Kimsuky, which the North Korean government…
Researchers observed the Gayfemboy botnet in early 2024 as a basic Mirai variant. Still, the…
Gravy Analytics, a prominent player in location intelligence, has reportedly fallen victim to a significant…
Google has released an update for its Chrome web browser, advancing to version 131.0.6778.264/.265 for…
The distinction between nation-state actors and organized cybercriminals is becoming increasingly blurred. Both groups now…
Washington State Attorney General Bob Ferguson filed a consumer protection lawsuit against T-Mobile for its…