Thursday, January 30, 2025
HomeBackdoorFileless Malware Installing Backdoor Via USB Flash Disks

Fileless Malware Installing Backdoor Via USB Flash Disks

Published on

SIEM as a Service

Follow Us on Google News

A Fileless Malware Discovered as “TROJ_ANDROM.SVN” that can ability to Create a Backdoor into Target Windows Computer which is installing via USB Flash Disks.

USB Flash Disk contained  2 Different Backdoor that is fully Encrypted and initially it abuse many Legitimate functions is the System.

Mostly Filess Malware infecting the computer Memory and vector involves some writing to the hard disk.

Its purpose is to reside in volatile system areas such as the system registry, in-memory processes and service areas.

Also Read:    Filelessmalware that uses PowerShell scripts from Window’s registry leading to Click Fraud Malware Campaign

How Does Fileless Malware Infection Chain Works

This Fileless Malware Discovered in USB flash disk which contains 2 malicious Backdoor files and both Detected as “TROJ_ANDROM.SVN”.

Both Files have the Different lengthy file name and Both Files have Different infection capability.

1.addddddadadaaddaaddaaaadadddddaddadaaaaadaddaa.addddddadadaaddaaddaaaadadddddadda

2. IndexerVolumeGuid

Once user Click the Malware, It will be Decrypted and Loaded into Memory and later it will create an auto start registry entry and run.

A shortcut with the target path %System%\cmd.exe /c start rundll32 {DLL file with long file name},{DLL’s export function} may also be used. These shortcut files may have appear to have the same name as the removable drive, tricking the user into clicking it. (We detect these shortcuts as LNK_GAMARUE.YYMN.)

This Decryptor’s file name serves as a Decryption key to  Decrypt the Malware.

Fileless Malware

Infection Flow Chart

Later, AutoStart Registry Entry Created by decrypted code and it will Serve as a Starting point for Execution Process.

Once Registry entry createdeventually  JS_POWMET.DE leading to the download and execution of a backdoor onto the affected system.

According to Trend Micro, After this Process, a second Backdoor wil be Detected as BBKDR_ANDROM.SMRA  and Drop dropped in the %AppData% folder with the filename ee{8 random characters}.exe. A shortcut to it is also created in the user startup folder, ensuring that this second backdoor is automatically executed.

End of the Result, This Second Backdoor take over the complete control of the system by Executing the  BBKDR_ANDROM.SMRA  Backdoor.

Registry entries Contained two URL’s and both used for Different Operating Systems that is one URL is used for Windows 10, another for earlier versions of Windows.

This Different URL allows for Different Attack based on the user’s operating system.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

New RDP Exploit Allows Attackers to Take Over Windows and Browser Sessions

Cybersecurity experts have uncovered a new exploit leveraging the widely used Remote Desktop Protocol...

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that...

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek,...

OPNsense 25.1 Released, What’s New!

The highly anticipated release of OPNsense 25.1 has officially arrived! Nicknamed "Ultimate Unicorn," this...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows

The QSC Loader service DLL named "loader.dll" leverages two distinct methods to obtain the...

Stealthy Steganography Backdoor Attacks Target Android Apps

BARWM, a novel backdoor attack approach for real-world deep learning (DL) models deployed on...