Monday, March 3, 2025
HomeBackdoorFileless Malware Installing Backdoor Via USB Flash Disks

Fileless Malware Installing Backdoor Via USB Flash Disks

Published on

SIEM as a Service

Follow Us on Google News

A Fileless Malware Discovered as “TROJ_ANDROM.SVN” that can ability to Create a Backdoor into Target Windows Computer which is installing via USB Flash Disks.

USB Flash Disk contained  2 Different Backdoor that is fully Encrypted and initially it abuse many Legitimate functions is the System.

Mostly Filess Malware infecting the computer Memory and vector involves some writing to the hard disk.

Its purpose is to reside in volatile system areas such as the system registry, in-memory processes and service areas.

Also Read:    Filelessmalware that uses PowerShell scripts from Window’s registry leading to Click Fraud Malware Campaign

How Does Fileless Malware Infection Chain Works

This Fileless Malware Discovered in USB flash disk which contains 2 malicious Backdoor files and both Detected as “TROJ_ANDROM.SVN”.

Both Files have the Different lengthy file name and Both Files have Different infection capability.

1.addddddadadaaddaaddaaaadadddddaddadaaaaadaddaa.addddddadadaaddaaddaaaadadddddadda

2. IndexerVolumeGuid

Once user Click the Malware, It will be Decrypted and Loaded into Memory and later it will create an auto start registry entry and run.

A shortcut with the target path %System%\cmd.exe /c start rundll32 {DLL file with long file name},{DLL’s export function} may also be used. These shortcut files may have appear to have the same name as the removable drive, tricking the user into clicking it. (We detect these shortcuts as LNK_GAMARUE.YYMN.)

This Decryptor’s file name serves as a Decryption key to  Decrypt the Malware.

Fileless Malware

Infection Flow Chart

Later, AutoStart Registry Entry Created by decrypted code and it will Serve as a Starting point for Execution Process.

Once Registry entry createdeventually  JS_POWMET.DE leading to the download and execution of a backdoor onto the affected system.

According to Trend Micro, After this Process, a second Backdoor wil be Detected as BBKDR_ANDROM.SMRA  and Drop dropped in the %AppData% folder with the filename ee{8 random characters}.exe. A shortcut to it is also created in the user startup folder, ensuring that this second backdoor is automatically executed.

End of the Result, This Second Backdoor take over the complete control of the system by Executing the  BBKDR_ANDROM.SMRA  Backdoor.

Registry entries Contained two URL’s and both used for Different Operating Systems that is one URL is used for Windows 10, another for earlier versions of Windows.

This Different URL allows for Different Attack based on the user’s operating system.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lazarus Hackers Tamper with Software Packages to Gain Backdoor Access to the Victims Device

A recent investigation conducted by STRIKE, a division of SecurityScorecard, has unveiled the intricate...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows

The QSC Loader service DLL named "loader.dll" leverages two distinct methods to obtain the...