Threat Advisory

Boolka Group Targets Websites with BMANAGER Malware Through SQL Injections

Threat: Malware
Threat Actor Name: Boolka
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new threat actor named Boolka has been identified, utilizing the infrastructure to deploy a modular trojan called BMANAGER. The discovery of this infrastructure revealed a landing page designed to distribute BMANAGER, serving as a test for a malware delivery platform based on the BeEF framework. Boolka has been active conducting opportunistic SQL injection attacks to infect websites with malicious JavaScript capable of intercepting user data.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new threat actor named Boolka has been identified, utilizing the infrastructure to deploy a modular trojan called BMANAGER. The discovery of this infrastructure revealed a landing page designed to distribute BMANAGER, serving as a test for a malware delivery platform based on the BeEF framework. Boolka has been active conducting opportunistic SQL injection attacks to infect websites with malicious JavaScript capable of intercepting user data.[emaillocker id="1283"]

The Boolka threat actor employs a multi-faceted attack methodology, starting with malicious JavaScript injections on compromised websites to capture and exfiltrate user input data. The infrastructure includes a modified Django admin page with an injected BeEF hook script for malware delivery. The BMANAGER trojan consists of various modules: a downloader, keylogger (BMLOG), data exfiltration tool (BMREADER), application hooker (BMHOOK), and file stealer (BMBACKUP). BMLOG captures keystrokes and stores them in a local SQL database, while BMREADER exfiltrates this data to a C2 server. BMHOOK leverages Windows hooks and APIs to monitor and log focused application details, and BMBACKUP steals files by retrieving paths from a C2 and exfiltrating files via encoded and compressed HTTPS GET requests. All components utilize a local SQL database with various tables for client GUIDs, C2 lists, keylogger data, application focus events, targeted applications, and files for exfiltration. BMANAGER's suspiciously signed certificate raises questions about its legitimacy.

The detection of Boolka's activities emphasizes the dynamic and sophisticated nature of modern cyber threats, showcasing their progression from basic SQL injection attacks to complex malware ecosystems like the BMANAGER trojan, which employs keyloggers, file stealers, and legitimate signing certificates. This evolution highlights the critical need for robust security measures, continuous web infrastructure monitoring, and collaborative threat intelligence efforts to effectively counteract such advanced threats and mitigate their impact.

THREAT PROFILE:

Tactic Technique Id Technique
Resource Development T1583 Acquire Infrastructure
T1584 Compromise Infrastructure
T1587 Develop Capabilities
T1588 Obtain Capabilities
T1608 Stage Capabilities
Initial Access T1189 Drive-by Compromise
T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
T1204 User Execution
T1569 System Services
 Persistence  T1543 Create or Modify System Process
 Discovery T1082 System Information Discovery
Lateral Movement T1210 Exploitation of Remote Services
Collection  T1005 Data from Local System
T1056 Input Capture
T1213 Data from Information Repositories
Command and Control  T1071 Application Layer Protocol
T1001 Data Obfuscation
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1565 Data Manipulation
 T1657 Financial Theft

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/06/new-cyberthreat-boolka-deploying.html

[/emaillocker]
crossmenu