Wednesday, December 11, 2024
HomeCyber AttackFakeBat Malware Weaponizing AnyDesk, Zoom, Teams & Chrome

FakeBat Malware Weaponizing AnyDesk, Zoom, Teams & Chrome

Published on

SIEM as a Service

Hackers target and weaponize AnyDesk, Zoom, Teams, and Chrome as these applications are widely used in a multitude of sectors.

Not only that, but even these widely used applications also provide access to many users and sensitive information.

Cybersecurity researchers at Sekoia identified that FakeBat malware has been actively weaponizing widely used applications, AnyDesk, Zoom, Teams, and Chrome.

- Advertisement - SIEM as a Service

FakeBat Malware Loader

In 2024, FakeBat loader malware has become a major threat that uses drive-by-download methods for propagation.

This is sold as Loader-as-a-Service on dark web platforms and masquerades itself through malvertising and social engineering tricks.

Mostly, it is used for launching various payloads such as botnets and infostealers, which have been also associated with ransomware attacks.

The malware’s operators have updated its capabilities to include MSIX format builds and digital signatures to bypass security measures.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

The prices of FakeBat range from $1,000-$5,000 per week or month, depending on the package. Sekoia said that FakeBat deliberately restricts its customer base to maintain control over distribution and reduce the risks of detection.

FakeBat’s distribution has evolved into a sophisticated operation that involves different strategies such as malvertising, software impersonation, and social engineering on social networks.

Compromised website displaying a fake web browser update popup (Source – Sekoia)

Another way this malware is distributed is through compromised websites, fake browser updates, and targeted campaigns such as the “getmess.io” web3 chat app scam.

Fake web3 chat application (Source – Sekoia)

FakeBat’s infrastructure consists of many C2 servers with changing communication patterns and obfuscation techniques.

The operators use specific domain naming conventions and host their servers on select ASNs.

They have implemented traffic filtering based on user attributes and recently enhanced evasion by anonymizing their domain registrations.

This shows how Fakebat’s conspirators are adaptable while seeking evasion from detection during expansion.

Researchers observed that the following software were targeted by the FakeBat malvertising campaigns:-

  • 1Password
  • Advanced SystemCare
  • AnyDesk
  • Bandicam
  • Blender
  • Braavos
  • Cisco Webex
  • Epic Games
  • Google Chrome
  • Inkscape
  • Microsoft OneNote
  • Microsoft Teams
  • Notion
  • OBS Studio
  • OpenProject
  • Play WGT Golf
  • Python Shapr3D
  • Todoist
  • Trading View
  • Trello
  • VMware
  • Webull
  • WinRAR
  • Zoom

Nowadays, threat actors prefer making use of fake software landing pages to share malware, and this is done through the practice of tracking campaigns.

Other observed sets contain entities like FIN7 and Nitrogen campaigns which circulate different kinds of malicious codes.

FakeBat, a widely distributed loader marketed as Malware-as-a-Service, uses multiple means of distribution and constantly modifies itself to avoid being identified.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Resecurity introduces Government Security Operations Center (GSOC) at NATO Edge 2024

Resecurity, a global leader in cybersecurity solutions, unveiled its advanced Government Security Operations Center...

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...

DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet

DMD Diamond - one of the oldest blockchain projects in the space has announced the...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...

DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet

DMD Diamond - one of the oldest blockchain projects in the space has announced the...