Threat Advisory

Fake Human-Verification Pages Open Browser to Execute Malicious Commands

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat is distributed through a bulletproof hosting provider, AS202412, which announces twenty-four /24s and has been allocated since. The lure domains are created using a naming grammar that includes tokens such as 'auth', 'authorization', 'code', 'verif', 'verification', 'enter', 'press', 'cdn', 'browser', and 'fingerprint'. These domains resolve to addresses within the ASN, including 178.16.52[.]101, which has been observed resolving twelve different domains in their telemetry. The technique involves a fake human-verification page that arrives through an ad or a link in an email. The page looks like a Cloudflare interstitial or a CAPTCHA and instructs the user to press Windows+R, paste a command into the Run dialog box, and then press Enter. However, one variant pastes a single short line without hiding anything.

The real command sits off-screen to the left and executes in memory using a built-in system utility or a built-in system utility. The malware uses various evasion techniques, including mixed-case file names and Unicode superscript characters. The malware communicates with its C2 server through DNS lookups, which can be blocked at the ASN level. However, the C2 server can also be resolved using a blockchain RPC gateway, making it harder to detect. The malware uses various techniques to hide its presence, including hiding the command in plain sight and using legitimate services such as URL shorteners and cloud storage. The threat actor has been observed reusing infrastructure and lures across different campaigns, suggesting a high level of organization and.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat is distributed through a bulletproof hosting provider, AS202412, which announces twenty-four /24s and has been allocated since. The lure domains are created using a naming grammar that includes tokens such as 'auth', 'authorization', 'code', 'verif', 'verification', 'enter', 'press', 'cdn', 'browser', and 'fingerprint'. These domains resolve to addresses within the ASN, including 178.16.52[.]101, which has been observed resolving twelve different domains in their telemetry. The technique involves a fake human-verification page that arrives through an ad or a link in an email. The page looks like a Cloudflare interstitial or a CAPTCHA and instructs the user to press Windows+R, paste a command into the Run dialog box, and then press Enter. However, one variant pastes a single short line without hiding anything.

The real command sits off-screen to the left and executes in memory using a built-in system utility or a built-in system utility. The malware uses various evasion techniques, including mixed-case file names and Unicode superscript characters. The malware communicates with its C2 server through DNS lookups, which can be blocked at the ASN level. However, the C2 server can also be resolved using a blockchain RPC gateway, making it harder to detect. The malware uses various techniques to hide its presence, including hiding the command in plain sight and using legitimate services such as URL shorteners and cloud storage. The threat actor has been observed reusing infrastructure and lures across different campaigns, suggesting a high level of organization and.[emaillocker id="1283"]

The ASN-level block is recommended as it stops the page load and prevents the malware from executing. However, this may not cover all stages of the attack, including cloud-hosted stages or blockchain-resolved C2 lookups. A static CIDR list can be used to block traffic at the ASN level, but it requires revalidation against BGP on a schedule due to the risk of reallocated space causing outages and false positives. Domain blocklists are not recommended as they lose to token grammars and compromised legitimate sites. DNS filtering is also not effective as it only catches resolver-mediated and off-chain C2 lookups. Network detection without blocking can find the campaign, reuse, and infrastructure but arrives after the paste every time.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Execution T1204.004 User Execution Malicious Copy and Paste
Persistence T1547.014 Boot or Logon Autostart Execution Active Setup
Defence Evasion T1027.010 Obfuscated Files or Information Command Obfuscation
Defence Evasion T1218.007 System Binary Proxy Execution Msiexec
Command and control T1071.001 Application Layer Protocol Web Protocols

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Command & Control B0030 C2 Communication
Persistence F0012 Registry Run Keys / Startup Folder
Command & Control E1105 Ingress Tool Transfer
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis E1027 Obfuscated Files or Information
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Discovery E1083 File and Directory Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu