Wednesday, February 19, 2025
HomeMalwareDangerous Underminer Exploit Kit Delivers a Cryptocurrency-mining Malware and Bootkit

Dangerous Underminer Exploit Kit Delivers a Cryptocurrency-mining Malware and Bootkit

Published on

SIEM as a Service

Follow Us on Google News

A new exploit kit dubbed Underminer spreading through advertising servers that delivers bootkit which affects system boot sectors and the cryptocurrency-mining malware called Hidden Mellifera.

Underminer manages to secure the malware transfers through encrypted transmission control protocol (TCP) and it packs malware as read-only filesystem ROM files.

Security researchers from Trend Micro detected the Underminer’s activity on July 17 at it is primarily targeting Asian countries. The encryption tunnel and dumb file format make payload challenging to analyze for researchers.

Underminer

The exploit appeared to be created in November 2017 and it exploiting the following vulnerabilities.

CVE-2016-0189 memory corruption vulnerability in Internet Explorer (IE)
CVE-2015-5119 use-after-free vulnerability in Adobe Flash Player
CVE-2018-4878 use-after-free vulnerability in Adobe Flash Player

Underminer Encrypted Tunnel and Capabilities

According to researchers, Underminer contains multiple functionalities such as browser profiling and filtering, preventing of client revisits, URL randomization, and asymmetric encryption of payloads.

When the user’s accessed the exploit kit’s landing page it detects the user’s browser Agent type and the Adobe Flash Player version. If the client profile, not suits for Underminer it redirect’s user’s to the normal site instead of causing an infection.

Also, it set’s a token with a browser cookie and if the user accesses the malicious URL again it redirects them to an HTTP page with 404 error message.

It protects the exploit code and the traffic by using an asymmetric RSA encryption and the symmetric algorithms RC4 or Rabbit.

Before the exploitation Underminer generates a random key and passes to command-and-control (C&C) server. the same key to be used for encrypting javascript and exploits.

Decryption of the exploit payload or javascript can be done only with the private key that Underminer’s operators know.

Underminer Exploitation

Threat actors behind exploit Underminer exploit multiple security flaws and has similar infection chain but differs with execution.

With the Internet Explorer (IE) Exploit CVE-2016-0189, a malicious javascript file downloaded and executed through regsvr32.exe and the malicious DLL loaded executed with rundll32.exe that retrieves the second stage payload.

The infection chain for flash exploit CVE-2015-5119 & CVE-2018-4878 is fileless, the infection starts with the shellcode executed through iexplorer.exe that downloads the malicious cabinet file executed with rundll32.exe that retrieves the second stage payload.

Underminer

The second payload downloads additional payloads via encrypted TCP tunnel and the third stage of the payload decodes them from romfs and execute it.

In the fourth stage, it coredll.bin reads the configuration files, checks the environment and then drops the files.coredll’s the main function is to migrate it self-based on the configuration. The coredll execution flow is migrated to another process which is usually signed by the manufacturer or currently running an AV program.

The fifth and the final stage of the payload, the setup2.pkg responsible for installing the bootkit from the romfs file and the pgfs.pkg installs the cryptocurrency-mining Malware. Trend Micro published a blog post along with the technical description.

“we expect Underminer to hone their techniques to further obfuscate the ways they deliver their malicious content and exploit more vulnerabilities while deterring security researchers from looking into their activities.” researchers said.

Mitigations

It is always recommended to update your application and to patch your system’s and network.

If the backdoor was already uploaded on an infected server, it is possible to block the communication between to immobilize the backdoor.

Deploying a backdoor shell protection systems to identify and intercept all malicious incoming request.

Also Read

Most Advanced Backdoor Obfuscation and Evasion Technique That used by Hackers

Hackers Distributing FELIXROOT Backdoor Malware using Microsoft Office Vulnerabilities

Malwarebytes New Browser Extension That Protects you From Visiting Malicious Websites

New Variant of Dangerous Kronos Banking Malware Spreading via Malicious Word Documents

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

CISA Warns of Active Exploitation of SonicWall SonicOS RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding...

CISA Issues Warning on Palo Alto PAN-OS Security Flaw Under Attack

CISA and Palo Alto Networks are scrambling to contain widespread exploitation of a critical...

Surge in IRS and Tax-Themed Cyber Attacks Driven by Fresh Domain Registrations

The months of January through April, marking the U.S. tax season, have seen a...

Critical Flaw in Apache Ignite (CVE-2024-52577) Allows Attackers to Execute Code Remotely

A severe security vulnerability (CVE-2024-52577) in Apache Ignite, the open-source distributed database and computing...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Weaponized PDFs Deliver Lumma InfoStealer Targeting Educational Institutions

A sophisticated malware campaign leveraging the Lumma InfoStealer has been identified, targeting educational institutions...

Cybercriminals Embedded Credit Card Stealer Script Within <img> Tag

Cybersecurity researchers have uncovered a new MageCart malware campaign targeting e-commerce websites running on...

EagerBee Malware Targets Government Agencies & ISPs with Stealthy Backdoor Attack

A sophisticated cyber espionage campaign leveraging the EagerBee malware has been targeting government agencies...