Threat Advisory

FIN7 Exploits Google Ads for NetSupport RAT Malware Distribution

Threat: Malware
Threat Actor Name: FIN7
Threat Actor Type: Financially Motivated
Targeted Region: Global
Alias: G0046, Carbon Spider, FIN7, Elbrus/Sangria Tempest, Carbanak, Calcium/Coreid, TAG-CR1, ITG14, Gold Niagara, ATK32, APT-C-11 , Navigator, Gold Waterfall, ELBRUS, G0008,TelePort Crew, Magecart Group 7
Threat Actor Region: Russia
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have several incidents involving the financially motivated threat group FIN7 were observed by. The group, known for its activities utilized malicious websites impersonating reputable brands to distribute malicious payloads. Notably, they leveraged sponsored Google Ads to lure users into downloading fake browser extensions, which were disguised as MSIX files, a Windows app packaging format.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have several incidents involving the financially motivated threat group FIN7 were observed by. The group, known for its activities utilized malicious websites impersonating reputable brands to distribute malicious payloads. Notably, they leveraged sponsored Google Ads to lure users into downloading fake browser extensions, which were disguised as MSIX files, a Windows app packaging format.[emaillocker id="1283"]

In the first case, users were lured into downloading fake browser extensions from malicious websites, triggering the execution of PowerShell scripts embedded within MSIX files. These scripts, upon execution, collected system information and communicated with command-and-control servers to download and execute the NetSupport RAT. Similarly, in the second case, a fake MSIX installer led to the installation of NetSupport RAT, followed by the deployment of additional malicious tools such as csvde.exe and svchostc.py. The threat actors utilized these tools for reconnaissance, persistence, and process injection, showcasing a modus operandi.

The incidents underscore the significance of exercising caution while interacting with online advertisements and downloading files from unknown sources. The deceptive use of signed MSIX files highlights the need for users to remain vigilant and verify file sources thoroughly. Despite being signed with seemingly legitimate company names, these files contained malicious payloads, emphasizing that certification does not guarantee safety. These observations emphasize the ongoing threat posed by sophisticated threat actors and the importance of robust cybersecurity practices.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
Defense Evasion  T1027 Obfuscated Files or Information
Discovery  T1087 Account Discovery
Collection T1560 Archive Collected Data
Command and Control T1071 Application Layer Protocol
T1105 Ingress Tool Transfer
T1573 Encrypted Channel

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/05/fin7-hacker-group-leverages-malicious.html

[/emaillocker]
crossmenu