Infostealers increasingly impact global security

Check Point Software’s latest threat index reveals a significant rise in infostealers like Lumma Stealer, while mobile malware like Necro continues to pose a significant threat, highlighting the evolving tactics used by cybercriminals across the globe.

cybercriminals infostealers rise

Last month researchers discovered an infection chain where fake CAPTCHA pages are being utilized to distribute Lumma Stealer malware, which has climbed to 4th place in the monthly top malware rankings.

This campaign is notable for its global reach, affecting multiple countries through two primary infection vectors: one involving cracked game download URLs and the other through phishing emails targeting GitHub users as an innovative new means of attack vector. The infection process misleads victims into executing a malicious script that has been copied to their clipboard, showcasing the increasing prevalence of infostealers as an effective means for cyber criminals to exfiltrate credentials and sensitive data from compromised systems.

Necro has infected various popular applications, including game mods available on Google Play, with a cumulative audience of over 11 million Android devices.

The malware employs obfuscation techniques to evade detection and utilizes steganography, which is the practice of concealing information within another message or physical object to avoid detection, to conceal its payloads.Once activated, it can display ads in invisible windows, interact with them, and even subscribe victims to paid services, highlighting the evolving tactics used by attackers to monetize their operations.

The rise of sophisticated infostealers underscores a growing reality. Cybercriminals are evolving their methods and leveraging innovative attack vectors. Organizations must go beyond traditional defenses, adopting proactive and adaptive security measures that anticipate emerging threats to counter these persistent challenges effectively.

Top malware families

FakeUpdates is the most prevalent malware this month with an impact of 6% worldwide organizations, followed by Androxgh0st with a global impact of 5%, and AgentTesla with a global impact of 4%.

FakeUpdates – FakeUpdates (AKA SocGholish) is a downloader written in JavaScript. It writes the payloads to disk prior to launching them. FakeUpdates led to further compromise via many additional malware, including GootLoader, Dridex, NetSupport, DoppelPaymer, and AZORult.

Androxgh0st – Androxgh0st is a botnet that targets Windows, Mac, and Linux, exploiting vulnerabilities in PHPUnit, Laravel Framework, and Apache Web Server to steal sensitive data.

AgentTesla – AgentTesla is an advanced RAT functioning as a keylogger and information stealer, which is capable of monitoring and collecting the victim’s keyboard input, system keyboard, taking screenshots, and exfiltrating credentials to a variety of software installed on a victim’s machine (including Google Chrome, Mozilla Firefox and the Microsoft Outlook email client).

Lumma Stealer – Lumma Stealer, also referred to as LummaC2, is a Russian-linked information-stealing malware that has been operating as a Malware-as-a-Service (MaaS) platform since 2022. As a typical information-stealer, LummaC2 focuses on harvesting various data from infected systems, including browser credentials and cryptocurrency account information.

Formbook – Formbook is marketed as Malware-as-a-Service. It is designed to steal credentials, gather screenshots, and download and execute files based on commands from its command and control serve.

NJRat – NJRat is a remote accesses Trojan, targeting mainly government agencies and organizations in the Middle East. NJRat infects victims via phishing attacks and drive-by downloads, and propagates through infected USB keys or networked drives, with the support of Command & Control server software.

AsyncRat – Asyncrat is a Trojan that targets the Windows platform. This malware sends out system information about the targeted system to a remote server. It receives commands from the server to download and execute plugins, kill processes, uninstall/update itself, and capture screenshots of the infected system.

Remcos – Remcos is a RAT that first appeared in the wild in 2016. Remcos distributes itself through malicious Microsoft Office documents, which are attached to SPAM emails, and is designed to bypass Microsoft Windowss UAC security and execute malware with high-level privileges.

Glupteba – Known since 2011, Glupteba is a backdoor that gradually matured into a botnet. By 2019 it included a C&C address update mechanism through public BitCoin lists, an integral browser stealer capability and a router exploiter.

Vidar – Vidar is an infostealer malware operating as malware-as-a-service that was first discovered in the wild in late 2018. The malware runs on Windows and can collect a wide range of sensitive data from browsers and digital wallets.

Top exploited vulnerabilities

Web Servers Malicious URL Directory Traversal (CVE-2010-4598,CVE-2011-2474,CVE-2014-0130,CVE-2014-0780,CVE-2015-0666,CVE-2015-4068,CVE-2015-7254,CVE-2016-4523,CVE-2016-8530,CVE-2017-11512,CVE-2018-3948,CVE-2018-3949,CVE-2019-18952,CVE-2020-5410,CVE-2020-8260) – There exists a directory traversal vulnerability On different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitize the URI for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.

Command Injection Over HTTP (CVE-2021-43936,CVE-2022-24086) – A command Injection over HTTP vulnerability has been reported. A remote attacker can exploit this issue by sending a specially crafted request to the victim. Successful exploitation would allow an attacker to execute arbitrary code on the target machine.

Zyxel ZyWALL Command Injection (CVE-2023-28771) – A command injection vulnerability exists in Zyxel ZyWALL. Successful exploitation of this vulnerability would allow remote attackers to execute arbitrary OS commands in the effected system.

Top mobile malwares

This month Joker in the 1st place in the most prevalent Mobile malware, followed by Necro and Anubis.

Joker – An android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware signs the victim silently for premium services in advertisement websites.

Necro – Necro is an Android Trojan Dropper. It is capable of downloading other malware, showing intrusive ads and stealing money by charging paid subscriptions.

Anubis – Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger, audio recording capabilities and various ransomware features. It has been detected on hundreds of different applications available in the Google Store.

Top ransomware groups

The data is based on insights from ransomware “shame sites” run by double-extortion ransomware groups which posted victim information. RansomHub is the most prevalent ransomware group this month, responsible for 17% of the published attacks, followed by Play with 10% and Meow with 5%.

RansomHubRansomHub, a rebranded version of Knight ransomware, is known for its sophisticated encryption techniques and aggressive campaigns targeting various platforms, including Windows, macOS, Linux, and particularly VMware ESXi environments.

PlayPlay Ransomware, which emerged in 2022, has targeted businesses and critical infrastructureacross North America, South America, and Europe, often exploiting vulnerabilities in systems like Fortinet SSL VPNs.

Meow – Meow Ransomware is a variant of Conti ransomware , known for encrypting a wide range of files on compromised systems and appending the “. MEOW” extension to them. It spreads through various vectors, including unprotected RDP configurations, email spam, and malicious downloads, and uses the ChaCha20 encryption algorithm to lock files, excluding “.exe” and text files.

Most targeted industries

This month education/research remained in the 1st place in the attacked industries globally, followed by government/military and communications.

Don't miss