Threat Advisory

BattleRoyal Exploits Email and False Browser Updates to Propagate DarkGate Malware

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Threat actor identified as BattleRoyal executed a series of sophisticated social engineering campaigns targeting organizations in the United States and Canada across diverse industries. The primary objective was to deploy the versatile DarkGate malware, showcasing a broad spectrum of tactics, techniques, and procedures (TTPs). While researchers refrained from definitively associating BattleRoyal with known threat actors, the intricacy and variety of its TTPs have posed challenges in attribution. This threat actor leverages phishing emails at scale, employs fake browser updates under the guise of the RogueRaticate campaign, and adeptly utilizes traffic distribution systems, malicious VBScript, steganography, and exploits a Windows Defender vulnerability in its operations.[/subscribe_to_unlock_form]

Summary:

Threat actor identified as BattleRoyal executed a series of sophisticated social engineering campaigns targeting organizations in the United States and Canada across diverse industries. The primary objective was to deploy the versatile DarkGate malware, showcasing a broad spectrum of tactics, techniques, and procedures (TTPs). While researchers refrained from definitively associating BattleRoyal with known threat actors, the intricacy and variety of its TTPs have posed challenges in attribution. This threat actor leverages phishing emails at scale, employs fake browser updates under the guise of the RogueRaticate campaign, and adeptly utilizes traffic distribution systems, malicious VBScript, steganography, and exploits a Windows Defender vulnerability in its operations.[emaillocker id="1283"]

BattleRoyal employs a multifaceted approach to deliver DarkGate, and more recently, the NetSupport remote control software. The tactics involve mass phishing emails, fake browser updates (as observed in the RogueRaticate campaign), and manipulation of traffic distribution systems (TDSs). The BattleRoyal cluster's activities involve a sophisticated attack chain, leveraging multiple traffic delivery systems (TDS) like 404 TDS and Keitaro TDS, coupled with .URL files exploiting CVE-2023-36025. The emails within these campaigns intricately utilize 404 TDS URLs, redirecting to Keitaro TDS, ultimately leading to the deployment of DarkGate. Another facet of this threat is the RogueRaticate campaign, identified for fake browser update requests that discreetly drop DarkGate payloads. An intriguing shift occurred , as DarkGate was replaced with NetSupport, a more established remote access tool. This dynamic evolution, coupled with the use of dual .URL files, showcases the actor's adaptability and underscores the overarching trend of cybercriminals adopting diverse and creative attack chains.

The BattleRoyal cluster's, marked by intricate attack chains and the interchange between DarkGate and NetSupport payloads, underscores a nuanced approach to malware delivery. DarkGate's information theft capabilities and NetSupport's potential for control over infected hosts demonstrate the actor's intent for comprehensive compromise and lateral movement within targeted environments. The actor's adept use of both email campaigns and compromised websites employing fake update lures showcases a multifaceted social engineering strategy aimed at enticing users into unwittingly installing the final malicious payload. This emerging threat landscape reinforces the imperative for robust cybersecurity measures and user awareness to counter increasingly sophisticated cybercriminal tactics.

Threat Profile:

 

References:

The following reports contain further technical details:

https://www.darkreading.com/cyberattacks-data-breaches/battleroyal-hackers-deliver-darkgate-rat

[/emaillocker]
crossmenu