Threat Advisory

Legitimate Software GuLoader And Remcos Turned As Cyberweapon

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The software advertised as legitimate has been increasingly used by cybercriminals. It discusses the case of Remcos RAT and GuLoader (CloudEyE Protector), which are positioned as legitimate tools but are primarily used by cybercriminals. The sets the stage for an investigation into the link between these tools and exposes their use in cybercriminal activities. It begins by dissecting GuLoader and Remcos, shedding light on the technical intricacies of GuLoader, a shellcode-based loader favored by cybercriminals. Additionally, it’s highlights GuLoader's affiliation with CloudEyE Protector, emphasizing the complexity of this cyber toolkit.[/subscribe_to_unlock_form]

Summary:

The software advertised as legitimate has been increasingly used by cybercriminals. It discusses the case of Remcos RAT and GuLoader (CloudEyE Protector), which are positioned as legitimate tools but are primarily used by cybercriminals. The sets the stage for an investigation into the link between these tools and exposes their use in cybercriminal activities. It begins by dissecting GuLoader and Remcos, shedding light on the technical intricacies of GuLoader, a shellcode-based loader favored by cybercriminals. Additionally, it’s highlights GuLoader's affiliation with CloudEyE Protector, emphasizing the complexity of this cyber toolkit.[emaillocker id="1283"]

A tool closely tied to Remcos and available on VgoStore. It outlines how these variants are used to crypt and safeguard malicious payloads, rendering them invisible to antivirus software. The analysis extends to different versions of Protect, including VBS and NSIS variants. Furthermore, it establishes a connection between GuLoader and CloudEyE, unveiling the evolution of GuLoader and its relentless commitment to core functionality while employing anti-analysis techniques. Lastly, the report unveils the malicious activities orchestrated by an individual known as EMINэM, affiliated with BreakingSecurity and VgoStore. EMINэM's involvement in malware attacks targeting Certified Public Accountants (CPAs) and accountants during the US tax season is revealed, with an identification of files linked to GuLoader and Remcos used in these nefarious operations. The report concludes by examining the financial dimensions, including cryptocurrency transactions and revenue streams originating from EMINэM's illicit endeavors, providing a holistic understanding of this cyber landscape.

It emphasizes that Remcos and GuLoader, despite their claims of legitimacy, are being used for malicious purposes by individuals like EMINэM. The individuals behind BreakingSecurity and VgoStore are exposed as deeply involved in cybercriminal activities, including the distribution of malware.

Threat Profile:

References:

The following reports contain further technical details:

https://research.checkpoint.com/2023/unveiling-the-shadows-the-dark-alliance-between-guloader-and-remcos/

[/emaillocker]
crossmenu