Hackers target Remote Desktop Protocol (RDP) via malware because it provides them with remote access to a victim’s computer or network, allowing them to:-
Cybersecurity researchers at IBM X-Force affirmed recently that in place of conventional frameworks like CobaltStrike, the Gootloader group unveiled GootBot, a new tool for C2 and lateral movement.
GootBot, a stealthy Gootloader variant for lateral movement, complicates detection. The group uses SEO poisoning to target victims, introducing their custom bot to avoid detections while rapidly spreading and deploying payloads.
GootBot is expanding its post-infection capabilities, enabling threat actors to remain hidden for longer by running encrypted PowerShell scripts. Besides this, Gootloader was previously usually utilized for initial access.
GootBot is a lean PS script with a single C2 server that infiltrates enterprise domains via hacked WordPress sites, posing a risk with undetected activity, reads the IBM X-Force report.
Hive0127 (aka UNC2565) has been active since 2014 and deploys Gootloader via SEO poisoning and hacked WordPress sites, enabling ransomware and more.
Gootloader begins with a user downloading an infected archive, leading to obfuscated JavaScript files placed strategically in %APPDATA%.
This virus uses stages that collect data and connect with compromised WordPress-based C2 servers to schedule activities for persistence and allow dynamic PowerShell execution.
Moreover, this new variant is a lightweight PowerShell script with a single C2 server, enabling:-
GootBot beacons every 60 seconds, adjustable with a specific string. It handles task results for child jobs from the C2, sending ‘E1’ for incomplete jobs and ‘E2’ for missing ones.
A modulo-based approach is used to obscure the string after Base64 encoding, which is similar to the trick used by Gootloader.
GootBot sends POST requests to its C2 server, splitting data if it’s over 100,000 chars. It spreads laterally, using various techniques to infect hosts.
Its C2 generates diverse payloads and deploys them automatically. WinRM, SMB, and WinAPI are used for lateral movement.
Environment variables store encrypted strings, reducing script size. GootBot spoofs PowerShell process arguments by creating new processes.
StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.
GootBot also runs a reconnaissance script that collects the following data:-
Here below, we have mentioned all the recommendations offered by the security researchers:-
Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…
A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin, formerly…