News: 1661855232

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

That 'clean' Google Translate app is actually Windows crypto-mining malware

(2022/08/30)


Watch out: someone is spreading cryptocurrency-mining malware disguised as legitimate-looking applications, such as Google Translate, on free software download sites and through Google searches.

The cryptomining Trojan, known as Nitrokod, is typically disguised as a clean Windows app and works as the user expects for days or weeks before its hidden Monero-crafting code is executed.

It's said that the Turkish-speaking group behind Nitrokod – which has been active since 2019 and was detected by Check Point Research threat hunters at the end of July – may already have infected thousands of systems in 11 countries. What's interesting is that the apps provide a desktop version to services generally only found online.

[1]

"The malware is dropped from applications that are popular, but don't have an actual desktop version, such as Google Translate, keeping the malware versions in demand and exclusive," Check Point malware analyst Moshe Marelus wrote in a [2]report Monday.

[3]

[4]

"The malware drops almost a month after the infection, and following other stages to drop files, making it very hard to analyze back to the initial stage."

Along with Google Translate, other software leveraged by Nitrokod include other translation applications – including Microsoft Translator Desktop – and MP3 downloader programs. On some sites, the malicious applications will boast about being "100% clean," though they are actually loaded with mining malware.

[5]Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

[6]Shout-out to whoever went to Black Hat and had North Korean malware on their PC

[7]77% of security leaders fear we're in perpetual cyberwar from now on

[8]Smartphone gyroscopes threaten air-gapped systems, researcher finds

Nitrokod has been successful using download sites such as Softpedia to spread its naughty code. According to Softpedia, the Nitrokod Google Translator app has been downloaded more than 112,000 times since December 2019.

According to Check Point, the Nitrokod programmers are patient, taking a long time and multiple steps to cover up the malware's presence inside an infected PC before installing aggressive cryptomining code. Such lengthy, multi-stage infection efforts allowed the campaign to run undetected by cybersecurity experts for years before finally being discovered.

[9]

"Most of their developed programs are easily built from the official web pages using a Chromium-based framework," he wrote. "For example, the Google translate desktop application is converted from the Google Translate web page using the CEF [Chromium Embedded Framework] project. This gives the attackers the ability to spread functional programs without having to develop them."

After the booby-trapped program is downloaded and the user launches the software, an actual Google Translate app, built as described above using Chromium, is installed and runs as expected. At the same time, quietly in the background the software fetches and saves a series of executables that eventually schedule one particular .exe to run every day once unpacked. This extracts another executable that connects to a remote command-and-control server, fetches configuration settings for the Monero miner code, and starts the mining process, with generated coins sent to miscreants' wallets. Some of the early-stage code will self destruct to cover its tracks.

"At this point, all related files and evidence are deleted and the next stage of the infection chain will continue after 15 days by the Windows utility schtasks.exe," Marelus wrote. "This way, the first stages of the campaign are separated from the ones that follow, making it very hard to trace the source of the infection chain and block the initial infected applications."

[10]

One stage also checks for known virtual-machine processes and security products, which might indicate the software is being analyzed by researchers. If one is found, the program will exit. If the program continues, it will add a firewall rule to allow incoming network connections.

Throughout the multiple stages, the attackers use password-protected RAR encrypted files to deliver the next stage to make them more difficult to detect.

Check Point researchers were able to study the cryptomining campaign through the vendor's Infinity extended detection and response (XDR) platform, Marelus claimed. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yw40L@0elFgNJQksD6BzxwAAAQo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw40L@0elFgNJQksD6BzxwAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw40L@0elFgNJQksD6BzxwAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/08/29/atlassian_bitbucket_critical_bug/

[6] https://www.theregister.com/2022/08/25/north_korean_malware_black_hat/

[7] https://www.theregister.com/2022/08/27/in-brief-security/

[8] https://www.theregister.com/2022/08/23/phone_gyroscopes_airgapped_systems/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw40L@0elFgNJQksD6BzxwAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw40L@0elFgNJQksD6BzxwAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



Clever catch

teknopaul

Must be hard to catch this sort of thing, those browser frameworks are essentially front ends to running arbitrary code off the Internet without all the cross site security checks.

Same can be said for most mobile apps.

"100% clean" is a dead giveaway tho, its straight out of the lexicon of Cut-me-own-throat Dibbler.

Re: Clever catch

JimboSmith

To quote Wallace of Wallace and Gromit fame……Now that’s clever. Are you reading this Baroness Harding, that is a sophisticated attack.

Re: Clever catch

b0llchit

...those browser frameworks are essentially front ends to running arbitrary code off the Internet...

And we spent so many years teaching people not to download executables from the internet and just run them... Now we have created an infrastructure to undermine basic security principles by clicking away in a browser.

Should we be happy or sad? I for one have tears in my eyes when I see all the crap trying to run in the browser. Luckily, when a site shows nothing without having scripts enabled, then they clearly have nothing to say to me and can be disregarded immediately and completely.

Re: Clever catch

teknopaul

The app in question was already installed as an .exe.

It was not run from a Web browser. It's using the same tech as a Web browser.

It's possible for any app to download mining software from the Internet and run it. Its not specific to apps using webkit and the like, point is it's harder to catch with static analisis.

Actually, you would be better off running the code in a normal Web browser because it's safer.

I have never seen anything fill up a vacuum so fast and still suck.
-- Rob Pike, on X.

Steve Jobs said two years ago that X is brain-damaged and it will be
gone in two years. He was half right.
-- Dennis Ritchie

Dennis Ritchie is twice as bright as Steve Jobs, and only half wrong.
-- Jim Gettys