Summary:[/subscribe_to_unlock_form]
Summary:[emaillocker id="1283"]
Recent reports indicate that Genesis Market, an underground marketplace, has been using various malware families to infect victims and steal information. Malware families like AZORult, Raccoon, Redline, and DanaBot have been commonly used by Genesis Market to populate their online store with stolen information. To keep up with the growing demand of their users, Genesis Market started actively recruiting sellers in February 2023. A joint international task force consisting of law enforcement agencies from 17 countries has successfully disrupted the operations of Genesis Market, a notorious marketplace for stolen browser cookies. The market had been a hub for criminals to sell stolen information to other cybercriminals for profit. As part of the operation, hundreds of Genesis Market users were approached, and house searches were conducted to gather evidence.

Execution Flow
The initial infection vector for Genesis Market's malware appears to be a file named "setup.exe," which contains multiple stages of malware. The executable's size is inflated with null padding to avoid sandbox execution. The first stage drops a DLL file named "yvibiajwi.dll" in the victim's temporary folder, which is then used to load and execute the third stage shellcode. The shellcode decrypts the rest of the binary, resulting in a PE file that is injected using process hollowing. The fourth stage of the malware downloads and executes another binary from the command-and-control server. The commodity malware that was installed in the victim's machine was a DanaBot, a well-known malware family that steals sensitive information from users' systems for sale.
In the final stage, a Chrome extension is installed on the victim's device to steal browser information such as cookies, browser history, and current tab information. The extension masquerades as the Google Drive extension and consists of configuration files, including main code and email injection code based on the exposed API of the Chromium engine. The malicious extension is installed via multiple stages of PowerShell, and the OperaGX, Brave, and Chrome shortcuts on the victim's device are recreated with an additional command-line interface flag to load the extension. The configuration files give information about the list of permissions that the plug-in requires, which allows access to sensitive data, such as cookies, current opened tabs, and the browser's history.
Furthermore, the malware can edit loaded web pages and remove headers related to the Content Security Policy mechanism, allowing the injection of code into any rendered web page. There is also a potential existence of plugins for other browsers, making porting the malware to a different browser simple, while porting the plugin to a different browser may require more work.
Indeed, the takedown of Genesis Market is a significant achievement in the fight against cybercrime. It demonstrates that international cooperation and collaboration among law enforcement agencies can be effective in disrupting criminal activities and bringing perpetrators to justice. However, it also highlights the ongoing need for vigilance and proactive measures to protect against cyber threats.
Threat Profile:
| Tactic | Technique ID | Technique |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| Persistence | T1176 | Browser Extensions |
| Defense Evasion | T1055 | Process Injection |
| Credential Access | T1539 | Steal Web Session Cookie |
| Discovery | T1082 | System Information Discovery |
| T1497 | Virtualization/Sandbox Evasion | |
| Collection | T1113 | Screen Capture |
| Command and control | T1071 | Application Layer Protocol |
| T1568 | Dynamic Resolution | |
| T1102 | Web Service | |
| T1090 | Proxy | |
| T1105 | Ingress Tool Transfer |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/04/fbi-cracks-down-on-genesis-market-119.html
[/emaillocker]