Saturday, October 5, 2024
HomeBackdoorFileless Malware Installing Backdoor Via USB Flash Disks

Fileless Malware Installing Backdoor Via USB Flash Disks

Published on

A Fileless Malware Discovered as “TROJ_ANDROM.SVN” that can ability to Create a Backdoor into Target Windows Computer which is installing via USB Flash Disks.

USB Flash Disk contained  2 Different Backdoor that is fully Encrypted and initially it abuse many Legitimate functions is the System.

Mostly Filess Malware infecting the computer Memory and vector involves some writing to the hard disk.

- Advertisement - EHA

Its purpose is to reside in volatile system areas such as the system registry, in-memory processes and service areas.

Also Read:    Filelessmalware that uses PowerShell scripts from Window’s registry leading to Click Fraud Malware Campaign

How Does Fileless Malware Infection Chain Works

This Fileless Malware Discovered in USB flash disk which contains 2 malicious Backdoor files and both Detected as “TROJ_ANDROM.SVN”.

Both Files have the Different lengthy file name and Both Files have Different infection capability.

1.addddddadadaaddaaddaaaadadddddaddadaaaaadaddaa.addddddadadaaddaaddaaaadadddddadda

2. IndexerVolumeGuid

Once user Click the Malware, It will be Decrypted and Loaded into Memory and later it will create an auto start registry entry and run.

A shortcut with the target path %System%\cmd.exe /c start rundll32 {DLL file with long file name},{DLL’s export function} may also be used. These shortcut files may have appear to have the same name as the removable drive, tricking the user into clicking it. (We detect these shortcuts as LNK_GAMARUE.YYMN.)

This Decryptor’s file name serves as a Decryption key to  Decrypt the Malware.

Fileless Malware

Infection Flow Chart

Later, AutoStart Registry Entry Created by decrypted code and it will Serve as a Starting point for Execution Process.

Once Registry entry createdeventually  JS_POWMET.DE leading to the download and execution of a backdoor onto the affected system.

According to Trend Micro, After this Process, a second Backdoor wil be Detected as BBKDR_ANDROM.SMRA  and Drop dropped in the %AppData% folder with the filename ee{8 random characters}.exe. A shortcut to it is also created in the user startup folder, ensuring that this second backdoor is automatically executed.

End of the Result, This Second Backdoor take over the complete control of the system by Executing the  BBKDR_ANDROM.SMRA  Backdoor.

Registry entries Contained two URL’s and both used for Different Operating Systems that is one URL is used for Windows 10, another for earlier versions of Windows.

This Different URL allows for Different Attack based on the user’s operating system.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Prince Ransomware Hits UK and US via Royal Mail Phishing Scam

A new ransomware campaign targeting individuals and organizations in the UK and the US...

Microsoft, DOJ Dismantle Domains Used by Russian FSB-Linked Hacking Group

Microsoft and the U.S. Department of Justice (DOJ) have successfully dismantled a network of...

Cloud Penetration Testing Checklist – 2024

Cloud Penetration Testing is a method of actively checking and examining the Cloud system...

Linux Malware perfctl Attacking Millions of Linux Servers

Researchers have uncovered a sophisticated Linux malware, dubbed "perfctl," actively targeting millions of Linux...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Researchers Backdoored Azure Automation Account Packages And Runtime Environments

Runtime environments offer a flexible way to customize Automation Account Runbooks with specific packages....

Hackers Using Supershell Malware To Attack Linux SSH Servers

Researchers identified an attack campaign targeting poorly secured Linux SSH servers, where the attack...

UNC2970 Hackers Attacking Job Seekers Using Weaponized PDF Reader

UNC2970, a North Korean cyber espionage group, used customized SumatraPDF trojans to deliver MISTPEN...