The threat is distributed through a bulletproof hosting provider, AS202412, which announces twenty-four /24s and has been allocated since. The lure domains are created using a naming grammar that includes tokens such as 'auth', 'authorization', 'code', 'verif', 'verification', 'enter', 'press', 'cdn', 'browser', and 'fingerprint'. These domains resolve to addresses within the ASN, including 178.16.52[.]101, which has been observed resolving twelve different domains in their telemetry. The technique involves a fake human-verification page that arrives through an ad or a link in an email. The page looks like a Cloudflare interstitial or a CAPTCHA and instructs the user to press Windows+R, paste a command into the Run dialog box, and then press Enter. However, one variant pastes a single short line without hiding anything.
The real command sits off-screen to the left and executes in memory using a built-in system utility or a built-in system utility. The malware uses various evasion techniques, including mixed-case file names and Unicode superscript characters. The malware communicates with its C2 server through DNS lookups, which can be blocked at the ASN level. However, the C2 server can also be resolved using a blockchain RPC gateway, making it harder to detect. The malware uses various techniques to hide its presence, including hiding the command in plain sight and using legitimate services such as URL shorteners and cloud storage. The threat actor has been observed reusing infrastructure and lures across different campaigns, suggesting a high level of organization and.[/subscribe_to_unlock_form]
The threat is distributed through a bulletproof hosting provider, AS202412, which announces twenty-four /24s and has been allocated since. The lure domains are created using a naming grammar that includes tokens such as 'auth', 'authorization', 'code', 'verif', 'verification', 'enter', 'press', 'cdn', 'browser', and 'fingerprint'. These domains resolve to addresses within the ASN, including 178.16.52[.]101, which has been observed resolving twelve different domains in their telemetry. The technique involves a fake human-verification page that arrives through an ad or a link in an email. The page looks like a Cloudflare interstitial or a CAPTCHA and instructs the user to press Windows+R, paste a command into the Run dialog box, and then press Enter. However, one variant pastes a single short line without hiding anything.
The real command sits off-screen to the left and executes in memory using a built-in system utility or a built-in system utility. The malware uses various evasion techniques, including mixed-case file names and Unicode superscript characters. The malware communicates with its C2 server through DNS lookups, which can be blocked at the ASN level. However, the C2 server can also be resolved using a blockchain RPC gateway, making it harder to detect. The malware uses various techniques to hide its presence, including hiding the command in plain sight and using legitimate services such as URL shorteners and cloud storage. The threat actor has been observed reusing infrastructure and lures across different campaigns, suggesting a high level of organization and.[emaillocker id="1283"]
The ASN-level block is recommended as it stops the page load and prevents the malware from executing. However, this may not cover all stages of the attack, including cloud-hosted stages or blockchain-resolved C2 lookups. A static CIDR list can be used to block traffic at the ASN level, but it requires revalidation against BGP on a schedule due to the risk of reallocated space causing outages and false positives. Domain blocklists are not recommended as they lose to token grammars and compromised legitimate sites. DNS filtering is also not effective as it only catches resolver-mediated and off-chain C2 lookups. Network detection without blocking can find the campaign, reuse, and infrastructure but arrives after the paste every time.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195 | Supply Chain Compromise | - |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Execution | T1204.004 | User Execution | Malicious Copy and Paste |
| Persistence | T1547.014 | Boot or Logon Autostart Execution | Active Setup |
| Defence Evasion | T1027.010 | Obfuscated Files or Information | Command Obfuscation |
| Defence Evasion | T1218.007 | System Binary Proxy Execution | Msiexec |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Command & Control | B0030 | C2 Communication |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Command & Control | E1105 | Ingress Tool Transfer |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Discovery | E1083 | File and Directory Discovery |
The following reports contain further technical details:
[/emaillocker]