Wednesday, April 30, 2025
HomeComputer SecurityHackers Embedded the Malicious Code Within WAV Audio Files to Gain Reverse...

Hackers Embedded the Malicious Code Within WAV Audio Files to Gain Reverse Shell Access

Published on

SIEM as a Service

Follow Us on Google News

Researchers observed a new malware campaign using WAV audio files to hide the malware and to avoid detection. Threat actors embedded the malicious code within the WAV audio files.

Based on BlackBerry Cylance threat researchers’ analysis, each WAV file contains a loader component to decode and executing malicious content embedded in audio files.

Similar techniques were observed between multiple threat actors, they used PNG (1,2) and JPEG files, employs steganography techniques to hide the malware.

- Advertisement - Google News

Miner and Metasploit code – WAV Audio

Further analysis reveals that some of the WAV files contain crypto miner script XMRig Monero CPU miner and others include Metasploit code used to establish a reverse shell.

Both of the WAV files use the same infrastructure, which indicates the campaign used to gain remote access over the victim networks and for monetary benefits.

Attackers use steganography methods to hide the malicious codes in the WAV files. Earlier this year, Symantec published a report about the Turla APT hacker group, the APT group uses the .wav files with Metasploit code embedded.

Researchers classified the loaders into three categories

  • Loaders that employ the Least Significant Bit (LSB) steganography to decode and execute a PE file.
  • Loaders that employ a rand()-based decoding algorithm to decode and execute a PE file.
  • Loaders that employ rand()-based decoding algorithm to decode and execute shellcode.

Steganography & Encoding Methods

The first type is based on the steganography method, the .wav file employees steganography method to extract the content.

Upon executing the audio file Song(.)wav, it executes a DLL in memory and triggers the export process, the exported file is an XMRig Monero CPU miner, which is designed to steal victim’s resources and to mine cryptocurrency, reads the blog post.

The second category is based on the rand()-based decoding algorithm used to hide the PE files, in this case, the audio files don’t have any music.

When the audio file is executed, the loader reads the file and executes the DLL in memory, the extracted file is the XMRig Monero CPU miner.

The third category is the rand()-based decoding algorithm to hide PE files, like the previous one, this audio file also contains white noise.

Upon executing the audio file the loader opens the PE files, decodes its contents and executes the shellcode. The Metasploit shellcode is capable of launching reverse shell access to the specified IP address.

Attackers continue to use innovative methods to compromise victim machines, in this campaign attackers used both steganography and other encoding techniques.

IoCs

 SHA-256 

595A54F0BBF297041CE259461AE8A12F37FB29E5180705EAFB3668B4A491CECC
843CD23B0D32CB3A36B545B07787AC9DA516D20DB6504F9CDFFA806D725D57F0
DA581A5507923F5B990FE5935A00931D8CD80215BF588ABEC425114025377BB1
DB043392816146BBE6E9F3FE669459FEA52A82A77A033C86FD5BC2F4569839C9
7DC620E734465E2F5AAF49B5760DF634F8EC8EEAB29B5154CC6AF2FC2C4E1F7C

IP
94.249.192.103

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data

A security researcher has uncovered a serious vulnerability resulting from incorrectly configured OAuth2 credentials...

AWS Defaults Open Stealthy Attack Paths Enabling Privilege Escalation and Account Compromise

A recent investigation by security researchers has exposed critical vulnerabilities in the default IAM...

China-Linked Hackers Targeting Organizational Infrastructure and High-Value Clients

A leading U.S.-based cybersecurity firm, sophisticated cyber-espionage campaigns attributed to Chinese state-sponsored actors have...

Docker Registry Vulnerability Lets macOS Users Access Any Registry Without Authorization

A recently discovered vulnerability in Docker Desktop for macOS is raising concerns in the developer and...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data

A security researcher has uncovered a serious vulnerability resulting from incorrectly configured OAuth2 credentials...

AWS Defaults Open Stealthy Attack Paths Enabling Privilege Escalation and Account Compromise

A recent investigation by security researchers has exposed critical vulnerabilities in the default IAM...

China-Linked Hackers Targeting Organizational Infrastructure and High-Value Clients

A leading U.S.-based cybersecurity firm, sophisticated cyber-espionage campaigns attributed to Chinese state-sponsored actors have...