Threat Advisory

Hackers Hijack Anti-Virus Software Using SbaProxy Hacking Tool

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new and advanced tool named SbaProxy has been identified, which is part of an evolving threat actor toolkit. This tool hijacks legitimate anti-virus software, such as those from Malwarebytes, BitDefender, and APEX, to carry out malicious activities undetected. By modifying these anti-virus components and using valid or counterfeit certificates, the threat actors have managed to disguise SbaProxy as legitimate software, making it difficult to detect. This tool can establish proxy connections through a command-and-control server, which could be leveraged for malicious activities, including selling proxy services.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new and advanced tool named SbaProxy has been identified, which is part of an evolving threat actor toolkit. This tool hijacks legitimate anti-virus software, such as those from Malwarebytes, BitDefender, and APEX, to carry out malicious activities undetected. By modifying these anti-virus components and using valid or counterfeit certificates, the threat actors have managed to disguise SbaProxy as legitimate software, making it difficult to detect. This tool can establish proxy connections through a command-and-control server, which could be leveraged for malicious activities, including selling proxy services.[emaillocker id="1283"]

 

The suspicious activity linked to seemingly legitimate anti-virus binaries was detected, leading to the identification of SbaProxy as part of a broader malicious campaign. SbaProxy operates by establishing a proxy connection between the C&C server and a target machine, allowing threat actors to route traffic through infected systems. The tool is distributed in multiple formats, with DLL and EXE samples being modified versions of legitimate anti-virus components. The modifications involve injecting malicious code while retaining most of the original, benign code. The binaries are signed with counterfeit certificates, some of which remain valid, making them difficult to detect. The malicious DLLs and EXEs mimic legitimate software closely, with only minor alterations that execute XOR-encrypted shellcode, establishing communication with the C&C server. The PowerShell variants replicate the same functionality, further enhancing the attack's resilience.

 

The discovery of SbaProxy highlights the increasing of threats, where weaponize trusted security tools to evade detection. By leveraging legitimate anti-virus software, these threat actors can operate stealthily, bypassing traditional security measures. The use of valid certificates and carefully crafted malicious binaries underscores the complexity of the threat. As the cyber threat landscape continues to evolve, it is crucial for organizations to remain vigilant and proactive in their defense strategies. The ongoing monitoring of this threat and the development of advanced detection techniques are essential in safeguarding against these attacks.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
 T1203 Exploitation for Client Execution
 Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1070 Indicator Removal
T1112 Modify Registry
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
Impact  T1485 Data Destruction

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/hackers-hijack-anti-virus-software-using-sbaproxy-hacking-tool/

[/emaillocker]
crossmenu