Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Attackers use stolen banking data as phishing lure to deploy BitRAT

Altszn.com by Altszn.com
January 4, 2023
in Monero
0
Attackers use stolen banking data as phishing lure to deploy BitRAT
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


In a case that highlights how attackers can leverage information from data breaches to enhance their attacks, a group of attackers is using customer information stolen from a Colombian bank in phishing attacks with malicious documents, researchers report. The group, which might have been responsible for the data breach in the first place, is distributing an off-the-shelf Trojan program called ​​BitRAT that has been sold on the underground market since February 2021.

Stolen data used to add credibility to future attacks

Researchers from security firm Qualys spotted the phishing lures that involved Excel documents with malicious documents but appeared to contain information about real people. Looking more into the information, it appeared the data was taken from a Colombian cooperative bank. After looking at the bank’s public web infrastructure, researchers found logs that suggested the sqlmap tool was used to perform an SQL injection attack. They also found database dump files that attackers created.

“Overall, 418,777 rows of sensitive data have been leaked of customers with details such as Cedula numbers (Columbian national ID), email addresses, phone numbers, customer names, payment records, salary, address, etc.,” the researchers said in their report. “As of today, we have not found this information shared on any of our darkweb/clearweb monitored lists.”

Sometimes attacker groups buy data on the dark web, but since this data didn’t appear in any public offerings it means it was either a private sale or the attackers behind the phishing attacks obtained it themselves.

This is a clear example of a threat that researchers have long warned about following any data breach: Even if the stolen data doesn’t appear to have immediate value or can be easily exploited for monetary gain or for account access, attackers can still use such data to add credibility to other attacks. Users are much more likely to fall for an email that includes personal information that only their bank or a trusted service provider will have.

Multi-stage droppers

The dropper mechanism in the Excel files is fairly sophisticated. First, a highly obfuscated macro script hidden inside the file is executed and generates an .inf file from hundreds of arrays that are reconstructued using arithmetic operations. The final .inf file is then executed using advpack.dll, a library that assists with hardware and software installs by reading and verifying .INF files.

The .INF file contains an encoded second-stage loader in the form of an DLL file that’s decoded using the Windows certutil.exe utility and executed using rundll32. This loader then uses the WinHTTP library to download the BitRAT payload from a GitHub repository. The GitHub account was created in November and hosted multiple such payloads.

These payloads were themselves obfuscated via SmartAssembly and reflectively load the BitRAT binary, which is itself obfuscated with DeepSea. Following the deployment process all the temporary files created by the various stagers are deleted and the payload and BitRAT binary are copied to the startup folder to achieve persistence.

This process that involves multiple layers of obfuscation, encoding, anti-debugging techniques, the use of various system utilities for execution, and reflective DLL loading is indicative of attackers being versed in malware creation and delivery.

BitRAT itself is a powerful and feature-rich Trojan that can perform data exfiltration, keylogging, DDoS attacks, payload execution, webcam and microphone recording, Monero mining, credential theft, and more. However, it’s available for as little as $20 on underground forums. Attackers’ choice of an off-the-shelf trojan instead of custom one could be the result of both convenience and the intention of making attribution difficult. Since this malware program is so cheap, it’s likely used by a lot of different groups.

Copyright © 2023 IDG Communications, Inc.



Read More: news.google.com

Tags: AttackersbankingBitRATdatadeployLureMonerophishingstolen
ADVERTISEMENT

Recent

AI scammers are now impersonating US government bigwigs, says FBI

AI scammers are now impersonating US government bigwigs, says FBI

May 16, 2025
Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

May 15, 2025
Cardano Eyes Milestone as Hoskinson Teases Blockchain’s First Privacy Stablecoin

Cardano Eyes Milestone as Hoskinson Teases Blockchain’s First Privacy Stablecoin

May 15, 2025

Categories

  • Bitcoin (4,836)
  • Blockchain (11,372)
  • Crypto (9,312)
  • Dark Web (545)
  • DeFi (8,376)
  • Ethereum (4,886)
  • Metaverse (7,490)
  • Monero (288)
  • NFT (1,459)
  • Solana (5,038)
  • Web3 (20,652)
  • Zcash (503)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    AI scammers are now impersonating US government bigwigs, says FBI

    AI scammers are now impersonating US government bigwigs, says FBI

    May 16, 2025
    Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

    Asset tokenization expected to speed capital flows, says Chainlink’s Nazarov

    May 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 103,978.00
    • ethereumEthereum (ETH) $ 2,587.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.43
    • bnbBNB (BNB) $ 658.41
    • solanaSolana (SOL) $ 172.92
    • usd-coinUSDC (USDC) $ 0.999806
    • dogecoinDogecoin (DOGE) $ 0.227135
    • cardanoCardano (ADA) $ 0.783557
    • tronTRON (TRX) $ 0.277409
    • staked-etherLido Staked Ether (STETH) $ 2,588.24
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,990.00
    • suiSui (SUI) $ 3.89
    • wrapped-stethWrapped stETH (WSTETH) $ 3,104.40
    • chainlinkChainlink (LINK) $ 16.34
    • avalanche-2Avalanche (AVAX) $ 23.96
    • stellarStellar (XLM) $ 0.296904
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hyperliquidHyperliquid (HYPE) $ 26.62
    • hedera-hashgraphHedera (HBAR) $ 0.200443
    • leo-tokenLEO Token (LEO) $ 8.85
    • bitcoin-cashBitcoin Cash (BCH) $ 400.39
    • the-open-networkToncoin (TON) $ 3.11
    • litecoinLitecoin (LTC) $ 100.69
    • polkadotPolkadot (DOT) $ 4.87
    • usdsUSDS (USDS) $ 0.999806
    • wethWETH (WETH) $ 2,593.40
    • moneroMonero (XMR) $ 338.99
    • pi-networkPi Network (PI) $ 0.860349
    • wrapped-eethWrapped eETH (WEETH) $ 2,758.82
    • bitget-tokenBitget Token (BGB) $ 5.02
    • pepePepe (PEPE) $ 0.000014
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,029.00
    • whitebitWhiteBIT Coin (WBT) $ 30.30
    • bittensorBittensor (TAO) $ 440.44
    • uniswapUniswap (UNI) $ 6.36
    • daiDai (DAI) $ 0.999985
    • nearNEAR Protocol (NEAR) $ 2.93
    • aaveAave (AAVE) $ 234.54
    • aptosAptos (APT) $ 5.41
    • okbOKB (OKB) $ 53.69
    • ondo-financeOndo (ONDO) $ 0.990009
    • kaspaKaspa (KAS) $ 0.118682
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.99
    • internet-computerInternet Computer (ICP) $ 5.53
    • ethereum-classicEthereum Classic (ETC) $ 19.27
    • crypto-com-chainCronos (CRO) $ 0.101190
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • bitcoinBitcoin (BTC) $ 103,978.00
    • ethereumEthereum (ETH) $ 2,587.78
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.43
    • bnbBNB (BNB) $ 658.41
    • solanaSolana (SOL) $ 172.92
    • usd-coinUSDC (USDC) $ 0.999806
    • dogecoinDogecoin (DOGE) $ 0.227135
    • cardanoCardano (ADA) $ 0.783557
    • tronTRON (TRX) $ 0.277409
    • staked-etherLido Staked Ether (STETH) $ 2,588.24
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 103,990.00
    • suiSui (SUI) $ 3.89
    • wrapped-stethWrapped stETH (WSTETH) $ 3,104.40
    • chainlinkChainlink (LINK) $ 16.34
    • avalanche-2Avalanche (AVAX) $ 23.96
    • stellarStellar (XLM) $ 0.296904
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hyperliquidHyperliquid (HYPE) $ 26.62
    • hedera-hashgraphHedera (HBAR) $ 0.200443
    • leo-tokenLEO Token (LEO) $ 8.85
    • bitcoin-cashBitcoin Cash (BCH) $ 400.39
    • the-open-networkToncoin (TON) $ 3.11
    • litecoinLitecoin (LTC) $ 100.69
    • polkadotPolkadot (DOT) $ 4.87
    • usdsUSDS (USDS) $ 0.999806
    • wethWETH (WETH) $ 2,593.40
    • moneroMonero (XMR) $ 338.99
    • pi-networkPi Network (PI) $ 0.860349
    • wrapped-eethWrapped eETH (WEETH) $ 2,758.82
    • bitget-tokenBitget Token (BGB) $ 5.02
    • pepePepe (PEPE) $ 0.000014
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 104,029.00
    • whitebitWhiteBIT Coin (WBT) $ 30.30
    • bittensorBittensor (TAO) $ 440.44
    • uniswapUniswap (UNI) $ 6.36
    • daiDai (DAI) $ 0.999985
    • nearNEAR Protocol (NEAR) $ 2.93
    • aaveAave (AAVE) $ 234.54
    • aptosAptos (APT) $ 5.41
    • okbOKB (OKB) $ 53.69
    • ondo-financeOndo (ONDO) $ 0.990009
    • kaspaKaspa (KAS) $ 0.118682
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.99
    • internet-computerInternet Computer (ICP) $ 5.53
    • ethereum-classicEthereum Classic (ETC) $ 19.27
    • crypto-com-chainCronos (CRO) $ 0.101190
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00