Saturday, October 12, 2024
HomeCyber Security NewsResearchers Uncover DiceLoader Malware Used to Attack Corporate Business

Researchers Uncover DiceLoader Malware Used to Attack Corporate Business

Published on

Malware protection

An intrusion set called FIN7 has been known to be operating since 2015 and is composed of Russian-speaking members. This threat group also pretends to be a company that recruits IT experts to hide their illegal activities. 

Targets of this threat group include retail, hospitality, and food service industries within different geographical areas such as the United States, the United Kingdom, Australia, and France. This group also affiliates members from other notorious threat actors such as BlackBasta, Lockbit, Darkside, and REvil.

The toolset arsenal used by them is called “Carbanak,” which includes malware like loaders, ransomware, or backdoors alongside a great part of custom malware (e.g., Carbanak Backdoor, Domino Loader, Domino Backdoor, DiceLoader, etc.). 

- Advertisement - SIEM as a Service
Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Among these, Diceloader is known to have been used for a long time and is still being used by the threat group. It is dropped using a PowerShell script with specific obfuscation and other malware of their toolset. This small-sized malware is capable of several functionalities that can perform various malicious actions.

DiceLoader execution (Source: Sekoia)
DiceLoader execution (Source: Sekoia)

DiceLoader Malware Attacking Corporates

The loader is a DLL that uses the “Reflective DLL Injection” module to inject the Diceloader main entry point into another process memory. The first function of this Diceloader is to set up the principal data structures and mechanisms for future executions.

It allocates four empty linked lists for connecting each part of the program to structure the data in memory. After this, the loader starts multiple threads, including threads, to receive, parse, and format incoming TCP packets from C2 servers and reads the SEIKO report.

Obfuscation Methods

Diceloader has two obfuscation methods. One is to deobfuscate the configuration C2 (IP address and Port), and the other is to deobfuscate the network communication. The first obfuscation method uses an XOR operation with a fixed key length of 31 bytes.

The second method uses a much more complex XOR obfuscation function with each byte (Cx) XORed with a byte of the key (Kx). To explain further, the second obfuscation is used twice, with a fixed key stored in the PE for the first time and with a key sent by the C2 at the runtime on the second time.

Fingerprint

The loader gathers victims’ system information and generates a unique identifier by concatenating the MAC address, the username, and the computer name and hashing them together. This fingerprint information is then sent to the C2 server.

Researchers created a fake Diceloader C2 for further investigation, revealing the communication type between the malware and the C2 server. The Diceloader received data from its C2 after declaring itself to the server with a unique sequence of bytes.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Foxit PDF Reader Vulnerability Let Attackers Execute Arbitary Code

Researchers recently disclosed six new security vulnerabilities across various software, as one critical vulnerability...