EXECUTIVE SUMMARY
A new threat actor named Boolka has been identified, utilizing the infrastructure to deploy a modular trojan called BMANAGER. The discovery of this infrastructure revealed a landing page designed to distribute BMANAGER, serving as a test for a malware delivery platform based on the BeEF framework. Boolka has been active conducting opportunistic SQL injection attacks to infect websites with malicious JavaScript capable of intercepting user data.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new threat actor named Boolka has been identified, utilizing the infrastructure to deploy a modular trojan called BMANAGER. The discovery of this infrastructure revealed a landing page designed to distribute BMANAGER, serving as a test for a malware delivery platform based on the BeEF framework. Boolka has been active conducting opportunistic SQL injection attacks to infect websites with malicious JavaScript capable of intercepting user data.[emaillocker id="1283"]
The Boolka threat actor employs a multi-faceted attack methodology, starting with malicious JavaScript injections on compromised websites to capture and exfiltrate user input data. The infrastructure includes a modified Django admin page with an injected BeEF hook script for malware delivery. The BMANAGER trojan consists of various modules: a downloader, keylogger (BMLOG), data exfiltration tool (BMREADER), application hooker (BMHOOK), and file stealer (BMBACKUP). BMLOG captures keystrokes and stores them in a local SQL database, while BMREADER exfiltrates this data to a C2 server. BMHOOK leverages Windows hooks and APIs to monitor and log focused application details, and BMBACKUP steals files by retrieving paths from a C2 and exfiltrating files via encoded and compressed HTTPS GET requests. All components utilize a local SQL database with various tables for client GUIDs, C2 lists, keylogger data, application focus events, targeted applications, and files for exfiltration. BMANAGER's suspiciously signed certificate raises questions about its legitimacy.
The detection of Boolka's activities emphasizes the dynamic and sophisticated nature of modern cyber threats, showcasing their progression from basic SQL injection attacks to complex malware ecosystems like the BMANAGER trojan, which employs keyloggers, file stealers, and legitimate signing certificates. This evolution highlights the critical need for robust security measures, continuous web infrastructure monitoring, and collaborative threat intelligence efforts to effectively counteract such advanced threats and mitigate their impact.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Resource Development | T1583 | Acquire Infrastructure |
| T1584 | Compromise Infrastructure | |
| T1587 | Develop Capabilities | |
| T1588 | Obtain Capabilities | |
| T1608 | Stage Capabilities | |
| Initial Access | T1189 | Drive-by Compromise |
| T1190 | Exploit Public-Facing Application | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| T1204 | User Execution | |
| T1569 | System Services | |
| Persistence | T1543 | Create or Modify System Process |
| Discovery | T1082 | System Information Discovery |
| Lateral Movement | T1210 | Exploitation of Remote Services |
| Collection | T1005 | Data from Local System |
| T1056 | Input Capture | |
| T1213 | Data from Information Repositories | |
| Command and Control | T1071 | Application Layer Protocol |
| T1001 | Data Obfuscation | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1565 | Data Manipulation |
| T1657 | Financial Theft |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/06/new-cyberthreat-boolka-deploying.html
[/emaillocker]