The ScrubCrypt obfuscation tool has been discovered to be utilized in attacks to disseminate the RedLine Stealer malware, and its new variant was being marketed in underground communities.
Threat actors use the ScrubCrypt obfuscation tool to help them avoid detection by antivirus software and initiate attacks that might otherwise be stopped.
RedLine Stealer is a well-known malware that can exfiltrate cryptocurrency wallets and credentials to attack users’ accounts through account takeover and fraud.
This malware aims to compromise accounts by stealing cookies, browser login information, and locally stored login credentials from users.
StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.
Through the creation of batch files, ScrubCrypt’s “marketing” presents the add-on to threat actors as a simple means of obfuscating executable files.
“This conversion from the executable file into a batch file—enables threat actors to slip attacks past many preventative measures that might otherwise identify them,” HUMAN’s Satori Threat Intelligence Team shared in a report with Cyber Security News.
Safeguards used by numerous email providers and messaging platforms prevent executable files from appearing as attachments in a primary (non-spam) mailbox. Furthermore, unlike executable files, bat files don’t trigger antivirus software’s detection.
The new build of ScrubCrypt build was offered to threat actors on a few dark web marketplaces, including Nulled Forum, Cracked Forum, and Hack Forums.
The website that is selling and hosting this new build of ScrubCrypt is registered and hosted in Russia, placing it out of the control of US and EU agencies in an attempt to elude law enforcement.
One HUMAN customer was reportedly the subject of this attack via its direct messaging platform. Threat actors had previously used RedLine Stealer to target this platform, but this was the first time they used this particular ScrubCrypt build.
Therefore, it is advised that companies implement safeguards that identify and prevent cookie-stealing attacks and alert users whose credentials have been compromised or stolen by other threats, especially those whose user platforms include direct or private messaging capabilities.
Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.
A very important message from the Norwegian National Cyber Security Centre (NCSC) says that Secure Socket Layer/Transport Layer Security (SSL/TLS)…
Linux is widely used in numerous servers, cloud infrastructure, and Internet of Things devices, which makes it an attractive target…
ViperSoftX malware, known for stealing cryptocurrency information, now leverages Tesseract, an open-source OCR engine, to target infected systems, which extracts…
Santander has confirmed that there was a major data breach that affected its workers and customers in Spain, Uruguay, and…
The U.S. government has offered a prize of up to $5 million for information that leads to the arrest and…
Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals,…