Friday, January 31, 2025
HomeMalwareDeathStalker Hacker Group's New PowerPepper Malware Evade Antivirus Detection to Bypass Windows

DeathStalker Hacker Group’s New PowerPepper Malware Evade Antivirus Detection to Bypass Windows

Published on

SIEM as a Service

Follow Us on Google News

Researchers uncovered a new Malvertising campaign PowerPepper from DeathStalker threat actor group that is active since 2012, and actively attacking various organizations around the world with financial motivation.

DeathStalker group does not fit under the traditional cybercrime group instead, researchers believe that the group is operating as a hack-for-hire service.

Attackers leveraged the anti-detection and antivirus evasion techniques to avoid detection and are used a method called “dead-drop resolvers” (DDRs) that helps attackers to host their obfuscated content hosted on major public web services like YouTube, Twitter, Reddit to target the victims.

PowerPepper considers a previously unknown implant that leveraged DNS over HTTPS as a C2 channel and spotted in wide that attacking various organizations in June 2020.

Attack using a spear phishing campaign to target the victims and using a Word document to drop the payload, and the malware has been continuously operating and developing.

PowerPepper Operation and Infection Process

Attackers cleverly operating the PowerPepper malware, and it is a Windows in-memory PowerShell backdoor that can execute remotely.

Also, it is leveraging various techniques such as detecting mouse movements, filtering the client’s MAC addresses, and adapting its execution flow to evade the AV detection and sandbox execution.

The command and control server using for this campaign based on the communications via DNS over HTTPS (DoH). inorder to establish a DoH request to a C2 server, PowerPepper initially tries to leverage Microsoft’s Excel as a Web client then comes back to PowerShell’s standard web client.

Attackers rely upon AES encryption to ensure the C2 communications content between the implant and servers is encrypted.

PowerPepper Delivery Chains

DeathStalker using two different types of Delivery Chain is Macro-based delivery chain and LNK-based delivery chain.

The macro-based delivery chain being uncovered back in July 2020 via a malicious Word document but the researchers unable to identify that how this malicious document has been distributed and believed that the item is either embedded as a spear-phishing email body or downloaded from a malicious link in a spear-phishing email as previously said.

According to Kaspersky’s report, the LNK-based delivery chain is a Windows shortcut file-based, and it is very much similar to macro-based, but there are two major changes.

  • the malicious macros logic is moved to malicious PowerShell scripts, and the first one is directly embedded in the shortcut file, so there are no more VBA macros;
  • the Word document from this chain is just a decoy and malicious files storage pack, and is downloaded from a remote location (a public file sharing service) instead of directly embedded somewhere.

There are 6 following tricks are used by this PowerPepper to perform the successful attacks which you can read detailed here.

  1. hide things in Word embedded shape properties (and make macro comments fun again)
  2.  use Windows Compiled HTML Help (CHM) files as archives for malicious files
  3. masquerade and obfuscate persistent files
  4. hide your implant between two ferns…
  5. get lost in Windows shell command translation
  6. kick start it all with a signed binary proxy execution

According to the tracking report, attackers are targeting several countries around the world, but the researchers could not precisely identify PowerPepper targets, but law and consultancy firms have been frequent targets of the actor.

Prevention Measures

  • Content hosts can regularly scan hosted files for malicious content, where regulations allow. 
  • Website owners and editors need to frequently and responsively update their CMS backends as well as associated plugins.
  • Ensure the protection on privileged and remote access, with client network address filtering, MFA and access logging on all backend endpoints.
  • Enterprise network users are strongly recommended to restrict script engine link PowerShell and  set up endpoint protection software on end-user computers and content servers.
  • Train employees and ensure them that they neveropen Windows shortcuts that were downloaded from a remote location or attached to an email, open attachments or click links in emails from unknown senders, or enable macros in documents from unverified sources.
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Critical D-Link Router Flaw Allows Attackers to Take Full Remote Control

A critical unauthenticated Remote Code Execution (RCE) vulnerability has been identified in D-Link's DSL-3788...

Massive Hacking Forum Network Dismantled by Authorities, Impacting 10M Users

Authorities have delivered a major blow to the cybercrime world by dismantling two of...

Microsoft Enhances M365 Bounty Program with New Services & Rewards Up to $27,000

Microsoft has announced updates to its Microsoft 365 (M365) Bug Bounty Program, offering expanded...

Tata Technologies Hit by Ransomware Attack, Some IT Services Suspended

Tata Technologies, a leading provider of engineering and IT services, has reported a ransomware...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations...

Lazarus Group Drop Malicious NPM Packages in Developers Systems Remotely

In a recent discovery by Socket researchers, a malicious npm package named postcss-optimizer has...