Threat Advisory

FakeAgent Campaign Infects Corporate Users

Threat: Malware Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An active malware campaign dubbed FakeAgent targets corporate users searching for desktop AI applications. Attackers employ malicious search advertisements to distribute a remote access trojan known as SectopRAT across various business sectors. This operation specifically aims to steal sensitive information, including browser credentials, credit card details, and personal files, while establishing persistent remote control over infected endpoints.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An active malware campaign dubbed FakeAgent targets corporate users searching for desktop AI applications. Attackers employ malicious search advertisements to distribute a remote access trojan known as SectopRAT across various business sectors. This operation specifically aims to steal sensitive information, including browser credentials, credit card details, and personal files, while establishing persistent remote control over infected endpoints.[emaillocker id="1283"]

By exploiting trust in popular software brands, the threat actors seek financial gain and long-term access to corporate networks through data theft. The attack chain initiates when users click sponsored search results that direct traffic to a fraudulent hosting page mimicking a legitimate vendor. Victims download a malicious executable that uses signed binaries and DLL sideloading to bypass security controls.

Once executed, the malware creates scheduled tasks for persistence and deploys additional payloads hidden within system folders. To avoid detection, the code checks for virtual machines before decrypting its final payload using graphics shaders. This process ultimately establishes a command-and-control channel via blockchain transactions, allowing operators to exfiltrate data and update infrastructure.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Initial Access T1189 Drive-by Compromise
Defense Evasion T1574.002 Hijack Execution Flow DLL Side-Loading
Persistence T1053.005 Scheduled Task/Job Scheduled Task
Defense Evasion T1562.001 Impair Defenses Disable or Modify Tools
Defense Evasion T1497.001 Virtualization/Sandbox Evasion System Checks
Defense Evasion T1027 Obfuscated Files or Information
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Command and Control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

The reports contain further technical details:
https://cybersecuritynews.com/fakeagent-campaign-malicious-bing-ads/

[/emaillocker]
crossmenu