Sophisticated Cryptocurrency Mining RETADUP Worm Goes Polymorphic to Evade Detection by Security Scanners

A new variant of cryptocurrency mining RETADUP worm found shifted to AutoHotKey version an open source windows programming language that used for creating hotkeys.

It allows users to automate repetitive tasks such as keyboard shortcuts, macros, and automation software.

This new variant of RETADUP Worm detected by Trend Micro, with their further analysis based on the C&C servers it matches to other samples and threat actors behind RETADUP had a history of cybercriminal cryptocurrency mining malware attacks.

New RETADUP Variant

RETADUP AutoHotKey resembles in a number of way’s to it previous AutoIt variant in techniques such as propagation, evasion&detection, and in the deployment of malicious Monero miner.

Researchers said “AutoHotKey is most likely because of its novelty as a scripting language. This entails the lack of known or prevalent tools that can actively detect and analyze malware written in AutoHotKey”.

RETADUP Versions
But still few of the new variant components using AutoIt, with the new version they used some form of obfuscation and polymorphism to help evade detection and the previous AutoIt-based variants don’t have this feature.

Attackers used AutoHotKey interpreter in propagation to run the malicious script, so if the system doesn’t have autokey it will be dropped and installed automatically. TrendMicro Published a detailed analysis report.

Similar to the previous versions AutoHotKey variant is also a botnet that downloads additional components from the command-and-control servers. When compared to the previous version it has slight changes with the networking part.

As like the previous versions of RETADUP it has AutoIt-compiled scripts that contain the Monero Miner XMRIG embedded binary file that injects directly into the memory of the following process.

Notepad.exe
Explorer.exe
SYSWOW64\wuapp.exe
SYSWOW64\svchost.exe
System32\wuapp.exe
System32\svchost.exe

Starting from 2018 cyber threat landscape shifted from Ransomware to Cryptocurrency mining attacks, attackers targeted a variety of web portals, Android devices, and variety of servers. Even the Ransomware and malware authors started to make their code by adding cryptocurrency miners because it becomes their strategy to maximize their profit.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…

1 day ago

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…

1 day ago

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…

1 day ago

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…

1 day ago

Beware! Fake Unpaid Tolls Messages Used in Phishing Attack to Steal Login Credentials

A surge in phishing text messages claiming unpaid tolls has been linked to a massive…

1 day ago

State Bar of Texas Confirms Data Breach, Begins Notifying Affected Consumers

The State Bar of Texas has confirmed a data breach following the detection of unauthorized…

1 day ago