[ << ALL_FEED ]

Malware flies, malware runs, malware sits in the sandbox ⏳

More in General

Malware flies, malware runs, malware sits in the sandbox ⏳

In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI).

A few days after the publication of the study, PT Sandbox helped prevent an attack on Russian defense and industrial enterprises, as well as the banking sector, which used an obfuscated variation of the PhantomRShell tool employed by PhantomCore.

🗓 This happened on August 24. At the same time, in open malware information aggregation systems, data on the samples appeared only on the morning of August 25, and a day later, the malware was still not detected by most popular antivirus solutions.

The attack began with an email from a completely legitimate sender—their account had been compromised. The attachment in archive format turned out to be a polyglot file assembled from three sequentially concatenated objects of different types: a DLL (containing a backdoor-type malicious payload), a PDF (to distract attention), and a ZIP archive (with an LNK file inside for persistence on the system).

Thanks to backdoor traffic analysis, the sandbox was able to correlate this sample with the PhantomRShell tool, which allows the attacker to remotely execute arbitrary code.

🤨 Details of the attack and how the hackers managed to send this payload from a legitimate sender are covered in an article on Habr.

#ti #apt #malware
@ptescalator

More from ti_author

More from ti_author

More in General