Friday, April 18, 2025
HomeMalwareLucifer - New Self-Propagating Malware Exploit Multiple Critical Bugs to Infect Windows...

Lucifer – New Self-Propagating Malware Exploit Multiple Critical Bugs to Infect Windows Devices

Published on

SIEM as a Service

Follow Us on Google News

Recently, the security experts have discovered a new self-propagating cryptojacking and DDoS-based malware “Lucifer” that are exploiting critical vulnerability to infect Windows devices. 

This vulnerability was discovered on May 29,2020, after investigating the vulnerability, the experts named it Lucifer, and this malware is capable in conducting DDoS attacks, and it is very well known for all kinds of exploits against different vulnerable Windows devices.

According to the Report from Palo Alto Networks, the main motive of the vulnerability was to infect the computer by attacking them with critical exploits, as they are aiming to take advantage of an “exhaustive” record of unpatched vulnerabilities.

- Advertisement - Google News

But, there are patches accesible for all the significant and high-severity bugs, but several firms got struck by the malware and not even applied for the fixes yet.

Lucifer: Cryptojacking and DDoS Campaign

Initially, the author of this malware has decided to name this malware as Satan DDoS, although there is already a malware that has a similar name as “Satan ransomware.” Therefore, the author, after having discussed with his team, decided to keep the name “Lucifer.” 

After deciding the name, the experts recognized two versions of Lucifer during the research. However, at first, they focused on version 1, and then they highlighted the changes and corrected them on version 2 in the next part.

Well, the malware “Lucifer” comprises a total of three sections, and all the three sections contain a binary for a special purpose.

The x86 support section includes a UPX-packed x86 version of XMRig 5.5.0, whereas the x64 resource section includes a UPX-packed x64 version of XMRig 5.5.0.

The last, the SMB section includes a binary, that contains a lot of equation groups such as EternalBlue and EternalRomance, and the vile DoublePulsar backdoor implant.

Lucifer: Version 2

Well, if we talk about the version 2 of “Lucifer,” then it is quite comparable to its forerunner. As its overall abilities and behaviors are very similar to the original one, and more importantly, it separates XMRig for cryptojacking, not only this, but it also manages C2 operation and develops itself by exploitation and brute-forcing vulnerability. 

Both the version shares a lot of similarities, but version 2 has some amazing differences, that makes is better than the version 1.

The experts also opined that the malware is growing in sophistication; that’s why they warn the users and ask them to be careful.

Moreover, the enterprises could defend themselves with simple security actions like implementing patches and changing and putting some strong passwords.

  • HFS found in the HTTP response: CVE-2014-6287
  • Jetty found in the HTTP response: CVE-2018-1000861
  • Servlet found in the HTTP response: CVE-2017-10271

No keywords found in the HTTP response:-

All these malware are quite dangerous, and experts have strongly recommended all the organizations to keep their system up-to-date, remove all weak credentials, and have a layer of protection so that it will help in an emergency situation.

You can find the complete Indicators of compromise.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Ransomware Attacks Surge 126%, Targeting Consumer Goods and Services Sector

The cybersecurity landscape witnessed a dramatic escalation in ransomware attacks, marking a concerning trend...

CrazyHunter Hacker Group Exploits Open-Source GitHub Tools to Target Organizations

A relatively new ransomware outfit known as CrazyHunter has emerged as a significant threat,...

Threat Actors Leverage Cascading Shadows Attack Chain to Evade Detection and Hinder Analysis

A sophisticated multi-layered phishing campaign was uncovered, employing a complex attack chain known as...

Microsoft Vulnerabilities Reach Record High with Over 1,300 Reported in 2024

The 12th Edition of the Microsoft Vulnerabilities Report has revealed a significant surge in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

LummaStealer Exploits Windows Utility to Run Remote Code Disguised as .mp4 File

The Cybereason Global Security Operations Center (GSOC) has shed light on the sophisticated tactics...

Gamaredon’s PteroLNK VBScript Malware Infrastructure and TTPs Uncovered by Researchers

Researchers have unearthed details of the Pterodo malware family, notably the PteroLNK variant used...

Agent Tesla Malware Uses Multi-Stage Attacks with PowerShell Scripts

Researchers from Palo Alto Networks have uncovered a series of malicious spam campaigns leveraging...