Gootloader malware updated with PowerShell, sneaky JavaScript
(2023/01/30)
- Reference: 1675107911
- News link: https://www.theregister.co.uk/2023/01/30/gootloader_mandiant_malware/
- Source link:
The operators behind Gootloader, a crew dubbed UNC2565, have upgraded the code in cunning ways to make it more intrusive and harder to find.
Researchers with Google-owned security shop Mandiant started seeing significant changes to the Gootloader malware package – also known as Gootkit – in November 2022, including using multiple variations of FONELAUNCH, a .NET-based loader, as well as some newly developed payloads and obfuscation techniques. There are also changes in its infection chain, including a new variant called Gootloader.PowerShell.
"These changes are illustrative of UNC2565's active development and growth in capabilities," the researchers wrote in a [1]report , adding that the group is the only one known to use the malware.
[2]
A Gootloader infection starts via a search engine optimization (SEO) poisoning attack, with a victim who is searching online for business-related documents, such as templates, agreements, or contracts, being lured into going to a website compromised by the criminal gang.
[3]
[4]
On the site are documents that actually are malicious ZIP archives housing malware written in JavaScript. Once the file is opened and the malware activated, more payloads like Cobalt Strike, FONELAUNCH, and SNOWCONE are added, as well as another collection of downloaders with payloads including the high-profile IcedID banking trojan.
Three months ago, Mandiant researchers began seeing the Gootloader.PowerShell variant, which includes an infection chain that that writes a second JavaScript file to the system's disk that reaches out to 10 hard-coded URLs, with each request containing encoded data about the compromised system, such the versions of Windows it's using, processes running and filenames.
This one isn't stopping
Gootloader in the months since May 2021 has used three variants of FONELAUNCH – FONELAUNCH.FAX, FONELAUNCH.PHONE, and FONELAUNCH.DIALTONE.
"The evolution of FONELAUNCH variants over time has allowed UNC2565 to distribute and execute a wider variety of payloads, including DLLs, .NET binaries, and PE files," the Mandiant researchers wrote.
[5]
UNC2565 also has upped efforts to make Gootloader more difficult to detect and track, expanding the number of obfuscation variants to three, another indication of the ongoing evolution of the cyberthreat. The first appeared in May 2021 as a small JavaScript file with a single obfuscated block of code.
A second one appeared in October 2021 inside trojanized jQuery libraries rather than hanging out on its own, a likely attempt to evade detection and slow any analysis of the malware, the researchers wrote. It hides itself among more than 10,000 lines of code, according to Mandiant.
[6]Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos
[7]FBI smokes ransomware Hive after secretly buzzing around gang's network for months
[8]UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish
[9]Miscreants sure do love ransacking cloud networks, more so than before
New samples of Gootloader with slight variations in the obfuscation code appeared in August 2022, extending the obfuscated string variables throughout the file – previous variants have them all on the same line – and inside a trojanized jit.js JavaScript file rather than jQuery. >The third obfuscation variant – seen in Gootloader.PowerShell – is a modified and more complex infection.
"This new variant contains additional string variables that are used in a second deobfuscation stage," the researchers wrote. "This new variant has been observed trojanizing several legitimate JavaScript libraries, including jQuery, Chroma.js, and Underscore.js."
Mandiant's report follows up one [10]released earlier this month by Trend Micro, which said that Gootloader was being used in a series of attacks on organizations in Australia's healthcare industry. Those analysts found that the threat group was continuing with the SEO poisoning technique for initial access but then abusing VLC Media Player and other legitimate tools to continue the infection.
[11]
"The threats targeting specific job sectors, industries, and geographic areas are becoming more aggressive," the Trend team wrote. "In addition to the continued targeting of the legal sector with the [keyword] 'agreement' [in the SEO poisoning effort], we also found that the current operation has also clearly sharpened its targeting capability by including the words 'hospital', 'health', 'medical', and names of Australian cities." ®
Get our [12]Tech Resources
[1] https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/11/09/sophos_infosec_predictions_2022_linux_targeting/
[7] https://www.theregister.com/2023/01/26/fbi_hive_ransomware/
[8] https://www.theregister.com/2023/01/27/uk_warns_against_russian_and/
[9] https://www.theregister.com/2023/01/20/cloud_networks_under_attack/
[10] https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Researchers with Google-owned security shop Mandiant started seeing significant changes to the Gootloader malware package – also known as Gootkit – in November 2022, including using multiple variations of FONELAUNCH, a .NET-based loader, as well as some newly developed payloads and obfuscation techniques. There are also changes in its infection chain, including a new variant called Gootloader.PowerShell.
"These changes are illustrative of UNC2565's active development and growth in capabilities," the researchers wrote in a [1]report , adding that the group is the only one known to use the malware.
[2]
A Gootloader infection starts via a search engine optimization (SEO) poisoning attack, with a victim who is searching online for business-related documents, such as templates, agreements, or contracts, being lured into going to a website compromised by the criminal gang.
[3]
[4]
On the site are documents that actually are malicious ZIP archives housing malware written in JavaScript. Once the file is opened and the malware activated, more payloads like Cobalt Strike, FONELAUNCH, and SNOWCONE are added, as well as another collection of downloaders with payloads including the high-profile IcedID banking trojan.
Three months ago, Mandiant researchers began seeing the Gootloader.PowerShell variant, which includes an infection chain that that writes a second JavaScript file to the system's disk that reaches out to 10 hard-coded URLs, with each request containing encoded data about the compromised system, such the versions of Windows it's using, processes running and filenames.
This one isn't stopping
Gootloader in the months since May 2021 has used three variants of FONELAUNCH – FONELAUNCH.FAX, FONELAUNCH.PHONE, and FONELAUNCH.DIALTONE.
"The evolution of FONELAUNCH variants over time has allowed UNC2565 to distribute and execute a wider variety of payloads, including DLLs, .NET binaries, and PE files," the Mandiant researchers wrote.
[5]
UNC2565 also has upped efforts to make Gootloader more difficult to detect and track, expanding the number of obfuscation variants to three, another indication of the ongoing evolution of the cyberthreat. The first appeared in May 2021 as a small JavaScript file with a single obfuscated block of code.
A second one appeared in October 2021 inside trojanized jQuery libraries rather than hanging out on its own, a likely attempt to evade detection and slow any analysis of the malware, the researchers wrote. It hides itself among more than 10,000 lines of code, according to Mandiant.
[6]Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos
[7]FBI smokes ransomware Hive after secretly buzzing around gang's network for months
[8]UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish
[9]Miscreants sure do love ransacking cloud networks, more so than before
New samples of Gootloader with slight variations in the obfuscation code appeared in August 2022, extending the obfuscated string variables throughout the file – previous variants have them all on the same line – and inside a trojanized jit.js JavaScript file rather than jQuery. >The third obfuscation variant – seen in Gootloader.PowerShell – is a modified and more complex infection.
"This new variant contains additional string variables that are used in a second deobfuscation stage," the researchers wrote. "This new variant has been observed trojanizing several legitimate JavaScript libraries, including jQuery, Chroma.js, and Underscore.js."
Mandiant's report follows up one [10]released earlier this month by Trend Micro, which said that Gootloader was being used in a series of attacks on organizations in Australia's healthcare industry. Those analysts found that the threat group was continuing with the SEO poisoning technique for initial access but then abusing VLC Media Player and other legitimate tools to continue the infection.
[11]
"The threats targeting specific job sectors, industries, and geographic areas are becoming more aggressive," the Trend team wrote. "In addition to the continued targeting of the legal sector with the [keyword] 'agreement' [in the SEO poisoning effort], we also found that the current operation has also clearly sharpened its targeting capability by including the words 'hospital', 'health', 'medical', and names of Australian cities." ®
Get our [12]Tech Resources
[1] https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/11/09/sophos_infosec_predictions_2022_linux_targeting/
[7] https://www.theregister.com/2023/01/26/fbi_hive_ransomware/
[8] https://www.theregister.com/2023/01/27/uk_warns_against_russian_and/
[9] https://www.theregister.com/2023/01/20/cloud_networks_under_attack/
[10] https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9hMD6QC0yvVZY61gjQHvgAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Browser code execution
Anonymous Coward
Green screens (or black and white if it’s a VT100) is the only way to go …. The future is behind us
Re: Browser code execution
Black Label1
Agree 100%
Users: Run Browser in a VM, clear the profile (rm -rf) from time to time
Devs: Cleanup your javascript libraries before serving files to the users, specially removing foreign-hosted code (like those bootstrap code often pointing to google servers)
Browser code execution
If browsers were just that without the ability to run code then the vast majority of these attacks would not be possible.
Unfortunately advertisers want the ability to execute code on the users computers (where the cost is born by the users) rather than on the servers (where they would have to bear the cost) and also want to be able to extract as much data about the users as possible..
For a safe browsing experience the browser should only execute HTML with no scripting or invoking other programs - however almost all sites now require the browser to support active scripting (shades of Internet Explorer and ActiveX!!). Now often even the website authors do not know what code the users are being asked to execute as their code pulls in code from other libraries which then pulls in further code.
It is getting to the point where the only safe way to run a browser is in a VM with no persistent storage using a Linux live CD (or DVD) image.
Even with Noscript, Spybot S&D and Norton Security (and using Firefox instead of IE or Edge) all too often browsing seems like treading a path through a minefield!!!
Icon for what should happen to the people who insist on browsers having active scripting ============>