Wednesday, January 22, 2025
HomeCyber Security NewsResearchers Uncover DiceLoader Malware Used to Attack Corporate Business

Researchers Uncover DiceLoader Malware Used to Attack Corporate Business

Published on

SIEM as a Service

Follow Us on Google News

An intrusion set called FIN7 has been known to be operating since 2015 and is composed of Russian-speaking members. This threat group also pretends to be a company that recruits IT experts to hide their illegal activities. 

Targets of this threat group include retail, hospitality, and food service industries within different geographical areas such as the United States, the United Kingdom, Australia, and France. This group also affiliates members from other notorious threat actors such as BlackBasta, Lockbit, Darkside, and REvil.

The toolset arsenal used by them is called “Carbanak,” which includes malware like loaders, ransomware, or backdoors alongside a great part of custom malware (e.g., Carbanak Backdoor, Domino Loader, Domino Backdoor, DiceLoader, etc.). 

Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Among these, Diceloader is known to have been used for a long time and is still being used by the threat group. It is dropped using a PowerShell script with specific obfuscation and other malware of their toolset. This small-sized malware is capable of several functionalities that can perform various malicious actions.

DiceLoader execution (Source: Sekoia)
DiceLoader execution (Source: Sekoia)

DiceLoader Malware Attacking Corporates

The loader is a DLL that uses the “Reflective DLL Injection” module to inject the Diceloader main entry point into another process memory. The first function of this Diceloader is to set up the principal data structures and mechanisms for future executions.

It allocates four empty linked lists for connecting each part of the program to structure the data in memory. After this, the loader starts multiple threads, including threads, to receive, parse, and format incoming TCP packets from C2 servers and reads the SEIKO report.

Obfuscation Methods

Diceloader has two obfuscation methods. One is to deobfuscate the configuration C2 (IP address and Port), and the other is to deobfuscate the network communication. The first obfuscation method uses an XOR operation with a fixed key length of 31 bytes.

The second method uses a much more complex XOR obfuscation function with each byte (Cx) XORed with a byte of the key (Kx). To explain further, the second obfuscation is used twice, with a fixed key stored in the PE for the first time and with a key sent by the C2 at the runtime on the second time.

Fingerprint

The loader gathers victims’ system information and generates a unique identifier by concatenating the MAC address, the username, and the computer name and hashing them together. This fingerprint information is then sent to the C2 server.

Researchers created a fake Diceloader C2 for further investigation, revealing the communication type between the malware and the C2 server. The Diceloader received data from its C2 after declaring itself to the server with a unique sequence of bytes.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887)

A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical...

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887)

A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical...

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...