Threat Advisory

Law Enforcement Agencies Cracks Down on Genesis Market

Threat: Malware
Targeted Region: U.S., E.U., U.K., Canada & Australia
Targeted Sector: Finance & Banking, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

Recent reports indicate that Genesis Market, an underground marketplace, has been using various malware families to infect victims and steal information. Malware families like AZORult, Raccoon, Redline, and DanaBot have been commonly used by Genesis Market to populate their online store with stolen information. To keep up with the growing demand of their users, Genesis Market started actively recruiting sellers in February 2023. A joint international task force consisting of law enforcement agencies from 17 countries has successfully disrupted the operations of Genesis Market, a notorious marketplace for stolen browser cookies. The market had been a hub for criminals to sell stolen information to other cybercriminals for profit. As part of the operation, hundreds of Genesis Market users were approached, and house searches were conducted to gather evidence.

 

Execution Flow

 

The initial infection vector for Genesis Market's malware appears to be a file named "setup.exe," which contains multiple stages of malware. The executable's size is inflated with null padding to avoid sandbox execution. The first stage drops a DLL file named "yvibiajwi.dll" in the victim's temporary folder, which is then used to load and execute the third stage shellcode. The shellcode decrypts the rest of the binary, resulting in a PE file that is injected using process hollowing. The fourth stage of the malware downloads and executes another binary from the command-and-control server. The commodity malware that was installed in the victim's machine was a DanaBot, a well-known malware family that steals sensitive information from users' systems for sale.

In the final stage, a Chrome extension is installed on the victim's device to steal browser information such as cookies, browser history, and current tab information. The extension masquerades as the Google Drive extension and consists of configuration files, including main code and email injection code based on the exposed API of the Chromium engine. The malicious extension is installed via multiple stages of PowerShell, and the OperaGX, Brave, and Chrome shortcuts on the victim's device are recreated with an additional command-line interface flag to load the extension. The configuration files give information about the list of permissions that the plug-in requires, which allows access to sensitive data, such as cookies, current opened tabs, and the browser's history.

Furthermore, the malware can edit loaded web pages and remove headers related to the Content Security Policy mechanism, allowing the injection of code into any rendered web page. There is also a potential existence of plugins for other browsers, making porting the malware to a different browser simple, while porting the plugin to a different browser may require more work.

Indeed, the takedown of Genesis Market is a significant achievement in the fight against cybercrime. It demonstrates that international cooperation and collaboration among law enforcement agencies can be effective in disrupting criminal activities and bringing perpetrators to justice. However, it also highlights the ongoing need for vigilance and proactive measures to protect against cyber threats.

 

Threat Profile:

Tactic Technique ID Technique
Execution T1204 User Execution
T1059 Command and Scripting Interpreter
Persistence T1176 Browser Extensions
Defense Evasion T1055 Process Injection
Credential Access T1539 Steal Web Session Cookie
Discovery T1082 System Information Discovery
T1497 Virtualization/Sandbox Evasion
Collection T1113 Screen Capture
Command and control T1071 Application Layer Protocol
T1568 Dynamic Resolution
T1102 Web Service
T1090 Proxy
T1105 Ingress Tool Transfer

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/04/fbi-cracks-down-on-genesis-market-119.html

[/emaillocker]
crossmenu