Cyber Security News

Researchers Uncover DiceLoader Malware Used to Attack Corporate Business

An intrusion set called FIN7 has been known to be operating since 2015 and is composed of Russian-speaking members. This threat group also pretends to be a company that recruits IT experts to hide their illegal activities. 

Targets of this threat group include retail, hospitality, and food service industries within different geographical areas such as the United States, the United Kingdom, Australia, and France. This group also affiliates members from other notorious threat actors such as BlackBasta, Lockbit, Darkside, and REvil.

The toolset arsenal used by them is called “Carbanak,” which includes malware like loaders, ransomware, or backdoors alongside a great part of custom malware (e.g., Carbanak Backdoor, Domino Loader, Domino Backdoor, DiceLoader, etc.). 

Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Among these, Diceloader is known to have been used for a long time and is still being used by the threat group. It is dropped using a PowerShell script with specific obfuscation and other malware of their toolset. This small-sized malware is capable of several functionalities that can perform various malicious actions.

DiceLoader execution (Source: Sekoia)

DiceLoader Malware Attacking Corporates

The loader is a DLL that uses the “Reflective DLL Injection” module to inject the Diceloader main entry point into another process memory. The first function of this Diceloader is to set up the principal data structures and mechanisms for future executions.

It allocates four empty linked lists for connecting each part of the program to structure the data in memory. After this, the loader starts multiple threads, including threads, to receive, parse, and format incoming TCP packets from C2 servers and reads the SEIKO report.

Obfuscation Methods

Diceloader has two obfuscation methods. One is to deobfuscate the configuration C2 (IP address and Port), and the other is to deobfuscate the network communication. The first obfuscation method uses an XOR operation with a fixed key length of 31 bytes.

The second method uses a much more complex XOR obfuscation function with each byte (Cx) XORed with a byte of the key (Kx). To explain further, the second obfuscation is used twice, with a fixed key stored in the PE for the first time and with a key sent by the C2 at the runtime on the second time.

Fingerprint

The loader gathers victims’ system information and generates a unique identifier by concatenating the MAC address, the username, and the computer name and hashing them together. This fingerprint information is then sent to the C2 server.

Researchers created a fake Diceloader C2 for further investigation, revealing the communication type between the malware and the C2 server. The Diceloader received data from its C2 after declaring itself to the server with a unique sequence of bytes.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Norway Recommends Replacing SSLVPN/WebVPN to Stop Cyber Attacks

A very important message from the Norwegian National Cyber Security Centre (NCSC) says that Secure Socket Layer/Transport Layer Security (SSL/TLS)…

2 days ago

New Linux Backdoor Attacking Linux Users Via Installation Packages

Linux is widely used in numerous servers, cloud infrastructure, and Internet of Things devices, which makes it an attractive target…

2 days ago

ViperSoftX Malware Uses Deep Learning Model To Execute Commands

ViperSoftX malware, known for stealing cryptocurrency information, now leverages Tesseract, an open-source OCR engine, to target infected systems, which extracts…

2 days ago

Santander Data Breach: Hackers Accessed Company Database

Santander has confirmed that there was a major data breach that affected its workers and customers in Spain, Uruguay, and…

2 days ago

U.S. Govt Announces Rewards up to $5 Million for North Korean IT Workers

The U.S. government has offered a prize of up to $5 million for information that leads to the arrest and…

2 days ago

Russian APT Hackers Attacking Critical Infrastructure

Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals,…

2 days ago