Sophisticated Cryptocurrency Mining RETADUP Worm Goes Polymorphic to Evade Detection by Security Scanners

A new variant of cryptocurrency mining RETADUP worm found shifted to AutoHotKey version an open source windows programming language that used for creating hotkeys.

It allows users to automate repetitive tasks such as keyboard shortcuts, macros, and automation software.

This new variant of RETADUP Worm detected by Trend Micro, with their further analysis based on the C&C servers it matches to other samples and threat actors behind RETADUP had a history of cybercriminal cryptocurrency mining malware attacks.

New RETADUP Variant

RETADUP AutoHotKey resembles in a number of way’s to it previous AutoIt variant in techniques such as propagation, evasion&detection, and in the deployment of malicious Monero miner.

Researchers said “AutoHotKey is most likely because of its novelty as a scripting language. This entails the lack of known or prevalent tools that can actively detect and analyze malware written in AutoHotKey”.

RETADUP Versions
But still few of the new variant components using AutoIt, with the new version they used some form of obfuscation and polymorphism to help evade detection and the previous AutoIt-based variants don’t have this feature.

Attackers used AutoHotKey interpreter in propagation to run the malicious script, so if the system doesn’t have autokey it will be dropped and installed automatically. TrendMicro Published a detailed analysis report.

Similar to the previous versions AutoHotKey variant is also a botnet that downloads additional components from the command-and-control servers. When compared to the previous version it has slight changes with the networking part.

As like the previous versions of RETADUP it has AutoIt-compiled scripts that contain the Monero Miner XMRIG embedded binary file that injects directly into the memory of the following process.

Notepad.exe
Explorer.exe
SYSWOW64\wuapp.exe
SYSWOW64\svchost.exe
System32\wuapp.exe
System32\svchost.exe

Starting from 2018 cyber threat landscape shifted from Ransomware to Cryptocurrency mining attacks, attackers targeted a variety of web portals, Android devices, and variety of servers. Even the Ransomware and malware authors started to make their code by adding cryptocurrency miners because it becomes their strategy to maximize their profit.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

DrayTek Devices Vulnerability Let Attackers Arbitrary Commands Remotely

The DrayTek Gateway devices, more specifically the Vigor2960 and Vigor300B models, are susceptible to a…

12 minutes ago

New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military

Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake "Army+" application websites,…

18 minutes ago

CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on a…

1 day ago

US Treasury Department Breach, Hackers Accessed Workstations

The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury Department,…

1 day ago

TrueNAS CORE Vulnerability Let Attackers Execute Remote Code

Security researchers Daan Keuper, Thijs Alkemade, and Khaled Nassar from Computest Sector 7 disclosed a…

1 day ago

New Botnet Exploiting D-Link Routers To Gain Control Remotely

Researchers observed a recent surge in activity from the "FICORA" and "CAPSAICIN," both variants of…

2 days ago