Categories: Mobile Attacks

InvisiMole – A Powerful Spyware Turn On Your Camera & Record Video, Audio, Take Picture

Newly discovered powerful InvisiMole Spyware attack targeted computer to turn on the video camera and record the videos, audio to hear whatever things happening to surround the victims and take the Picture.

Also, it has the ability to steal the various sensitive information of the victim’s computer by closely monitoring the victims actvities.

InvisiMole is one of the powerful spyware and it actively attacking many victims around the world since 2013 and now it discovered in Ukraine and Russia based targeted users computer.

It Contains 2 malicious component and both have rich backdoors actvities and it performs to steal and gather information as much as they can from the targeted machine.

Especially it is capable of remotely activating the microphone on the compromised computer and capturing sounds and audio recordings that will be misused by various purposes.

How Does InvisiMole Spyware Works

Initially, InvisiMole Spyware launching through hijacking the DLL(Dynamic-link Library) using the method called DLL Hijacking.

It has both  32-bit and 64-bit versions of the malware and both variant using persistence technique to working with both architectures.

Apart from the DLL Hijacking it using another entry point by exporting the function called GetDataLength which help to launch the payload.

Malware authors cleverly set to zero values PE timestamps manually so the exact time of the compilation is unknown.

Attackers encrypting the strings, internal files, configuration data and network communication to make it more stealthy and maintain the Persistence.

Later the module communicate with its C&C server even if there is a proxy configured on the infected computer and it also has an ability to communicate with C2 server using locally-configured proxies if the connection is unsuccessful.

According to ESET, After successfully registering the victim with the C&C server, additional data are downloaded, which are to be interpreted on the local computer as backdoor commands.

Commands will perform to collect some basic system information and it added the spyware future into the system.

The attack could remotely turn on the system microphone on the compromised computer and capturing sounds.

Also, InvisiMole Spyware can interfere with the victim’s privacy is by taking screenshots using another backdoor commands.

“The malware also monitors all fixed and removable drives mapped on the local system. Whenever a new drive is inserted, it creates a list of all the files on the drive and stores it encrypted in a file.”

All of the collected data can ultimately be sent to the attackers when the appropriate command is issued. ESET said.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Threat Actors Leverage Email Bombing to Evade Security Tools and Conceal Malicious Activity

Threat actors are increasingly using email bombing to bypass security protocols and facilitate further malicious…

7 hours ago

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral to…

7 hours ago

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers, following…

7 hours ago

Threat Actors Exploit Legitimate Crypto Packages to Deliver Malicious Code

Threat actors are using open-source software (OSS) repositories to install malicious code into trusted applications,…

7 hours ago

Tycoon 2FA Phishing Kit Uses Advanced Evasion Techniques to Bypass Endpoint Detection Systems

The notorious Tycoon 2FA phishing kit continues its evolution with new strategies designed to slip…

7 hours ago

Hands-On Labs: The Key to Accelerating CMMC 2.0 Compliance

INE Security Highlights How Practical, immersive training environments help defense contractors meet DoD cybersecurity requirements…

11 hours ago