[ << ALL_FEED ]

Big Browser is watching you

More in General

Big Browser is watching you 👹
The cyber intelligence group has recorded a new campaign using an updated stealer Unicorn, which began in mid-February and continues to this day. The targets of the attacks are the public sector, and they are being carried out by a previously unidentified hacker group.

The attackers send phishing emails with a topic related to the Special Military Operation, containing attached archives with a malicious HTA file (screenshot 1). This file contains obfuscated code and has a name matching the subject of the email. When opened, a decoy document is launched (screenshot 2), along with malicious code (via the window_OnLoad event).

The malware attempts to mimic Yandex Browser. The malicious script creates VBA files at the path %USERPROFILE%\AppData\Local\YandexUpdate, adds the payload to the registry HKCU\Software\YandexUpdate (screenshots 3, 4), registers VBA files in autorun via the registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and also registers tasks in the scheduler using schtasks.

🔤 Initially, the attackers used three scripts:

• log01.vbs — traverses user directories, analyzes the contents of specific folders, and saves files with specified extensions (.pdf, .txt, .doc, .docx, .rtf, .odt, .xls, .xlsx, .ods, .csv, .jpg, .png, .zip, .rar).
• log02.vbs — steals credentials from Telegram and browsers (from Chrome, Edge, Opera, Yandex Browser).
• log03.vbs — transmits the collected data to the command server.

👾 In recent attacks, the group modified and expanded the malware’s functionality:

• In crash_report.vbs (formerly log01.vbs), the list of file extensions for collection has been expanded (.vsdx, .vdx, .7z, .tar, .jpeg, .cdr, .kmz, .kml, .aqe). Importantly, the extensions .kml and .kmz, used in military topography, were added.
• Using service_report.vba, the attackers attempted to obtain a list of all flash drives, but the script turned out to be non-functional.
• A self-defense mechanism was added: update_logging.vbs restores deleted malicious files by loading their contents from the registry.

⚠️ It is important to note that the VBA scripts are not detected by antivirus solutions, as they read values from the registry and execute malicious code directly. This complicates the detection process (screenshot 5).

Analysis of the attack indicates the evolution of the attackers’ methodology. Additionally, it is worth noting that the group shows interest in extensions related to cartography. This may indicate a specific target or a strategic interest in this area.

IoCs

Domain
vm-tiktok.org

Hash sums
096c340e9a20476a191721e6eaeedcc2
0debff602f2912127c562839c7fcd3d7
e25042fba726356d7e88efe0608a4e36
290a4cff70029ca2a0095a3e3a8b19e7
65ef77db51277a046f76f21a59dee9e0
80bc350629a1ba59b2a19b9029feece5 
d0f9fadbf157a8236b88cfc03f17a811 
4feaa6c50348641799a8f56e76cd52e7
Code language: plaintext (plaintext)


#TI #APT #Malware #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General