EXECUTIVE SUMMARY
A new and advanced tool named SbaProxy has been identified, which is part of an evolving threat actor toolkit. This tool hijacks legitimate anti-virus software, such as those from Malwarebytes, BitDefender, and APEX, to carry out malicious activities undetected. By modifying these anti-virus components and using valid or counterfeit certificates, the threat actors have managed to disguise SbaProxy as legitimate software, making it difficult to detect. This tool can establish proxy connections through a command-and-control server, which could be leveraged for malicious activities, including selling proxy services.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new and advanced tool named SbaProxy has been identified, which is part of an evolving threat actor toolkit. This tool hijacks legitimate anti-virus software, such as those from Malwarebytes, BitDefender, and APEX, to carry out malicious activities undetected. By modifying these anti-virus components and using valid or counterfeit certificates, the threat actors have managed to disguise SbaProxy as legitimate software, making it difficult to detect. This tool can establish proxy connections through a command-and-control server, which could be leveraged for malicious activities, including selling proxy services.[emaillocker id="1283"]
The suspicious activity linked to seemingly legitimate anti-virus binaries was detected, leading to the identification of SbaProxy as part of a broader malicious campaign. SbaProxy operates by establishing a proxy connection between the C&C server and a target machine, allowing threat actors to route traffic through infected systems. The tool is distributed in multiple formats, with DLL and EXE samples being modified versions of legitimate anti-virus components. The modifications involve injecting malicious code while retaining most of the original, benign code. The binaries are signed with counterfeit certificates, some of which remain valid, making them difficult to detect. The malicious DLLs and EXEs mimic legitimate software closely, with only minor alterations that execute XOR-encrypted shellcode, establishing communication with the C&C server. The PowerShell variants replicate the same functionality, further enhancing the attack's resilience.
The discovery of SbaProxy highlights the increasing of threats, where weaponize trusted security tools to evade detection. By leveraging legitimate anti-virus software, these threat actors can operate stealthily, bypassing traditional security measures. The use of valid certificates and carefully crafted malicious binaries underscores the complexity of the threat. As the cyber threat landscape continues to evolve, it is crucial for organizations to remain vigilant and proactive in their defense strategies. The ongoing monitoring of this threat and the development of advanced detection techniques are essential in safeguarding against these attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1070 | Indicator Removal |
| T1112 | Modify Registry | |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/hackers-hijack-anti-virus-software-using-sbaproxy-hacking-tool/