Summary:
A persistent and concerning cyber threat has been detected, involving the misuse of the legitimate Windows software packaging tool, Advanced Installer, by malicious actors. Since November 2021, these cybercriminals have been utilizing Advanced Installer to bundle reputable software installers, such as Adobe Illustrator, Autodesk 3ds Max, and SketchUp Pro, with malicious scripts. These malevolent scripts are executed using Advanced Installer's Custom Actions feature, subsequently leading to the installation of malicious payloads. The primary objectives of these attacks are to establish backdoors, deploy cryptocurrency-mining malware, and exploit the high GPU power demands of 3-D modeling and graphic design software.[/subscribe_to_unlock_form]
Summary:
A persistent and concerning cyber threat has been detected, involving the misuse of the legitimate Windows software packaging tool, Advanced Installer, by malicious actors. Since November 2021, these cybercriminals have been utilizing Advanced Installer to bundle reputable software installers, such as Adobe Illustrator, Autodesk 3ds Max, and SketchUp Pro, with malicious scripts. These malevolent scripts are executed using Advanced Installer's Custom Actions feature, subsequently leading to the installation of malicious payloads. The primary objectives of these attacks are to establish backdoors, deploy cryptocurrency-mining malware, and exploit the high GPU power demands of 3-D modeling and graphic design software.[emaillocker id="1283"]
The attackers predominantly target users in French-speaking regions, notably France and Switzerland, with some infections observed in countries like the United States, Canada, Algeria, Sweden, Germany, Tunisia, Madagascar, Singapore, and Vietnam. The victims span various industries, including architecture, engineering, construction, manufacturing, and entertainment, which rely on powerful graphics cards suitable for cryptocurrency mining. The malicious payloads include the M3_Mini_Rat client stub, facilitating remote access, and cryptocurrency-mining malware like PhoenixMiner and lolMiner. These attackers have shown an adaptability to switch between mining different cryptocurrencies, with Ethereum Classic and FLUX (ZelHash) being notable targets.
The attack methodology involves two distinct approaches: one to establish a backdoor using M3_Mini_Rat, and the other to implant cryptocurrency miners like PhoenixMiner and lolMiner. While the initial infection vector remains undetermined, it's crucial to remain vigilant against these threats. The attackers use Advanced Installer's features to deploy malicious scripts, compromise victims' systems, and potentially inflict significant financial and operational damage. Therefore, organizations, especially those in the targeted industries and regions, should bolster their cybersecurity measures to detect and mitigate such threats effectively. Regular software updates, employee training, and advanced threat detection technologies can be instrumental in safeguarding against these ongoing cyberattacks.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/09/cybercriminals-weaponizing-legitimate.html
[/emaillocker]