Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
During March 2023, an ongoing malware operation was discovered that targeted more than 8,000 victims in North America, Italy, and France. The attackers utilized SEO poisoning and social engineering techniques to lure tech-savvy users, particularly IT personnel, into installing backdoored, cracked versions of well-known PC maintenance software such as "EaseUS Partition Master" and "Driver Easy Pro." The malicious campaign was traced back to a worldwide malware operation known as NullMixer, which is designed to provide infection services to criminal threat actors.
The attack was initiated through a series of YouTube videos promoting the cracked versions of the software, with one of them featuring a masked hacker explaining how to use the crack linked in the video description. The attackers used Bitly shortener and a BlogSpot account to protect the malicious code, which was then stored in an encrypted zip archive hosted on Mega.nz. The payload delivered by NullMixer remained substantially the same, consisting of a WinRAR executable archive containing multiple binaries that were auto launched on click. The malware delivered during this attack included two unknown loaders entering the MaaS and PPI businesses, namely CrashedLoader and Koi, and a controversial, potentially North-Korean linked piece of malware.
During the investigation, it was discovered that the attackers were evolving their social engineering techniques by producing YouTube videos that contained instructions to download and run the backdoored pirate software. The attackers packed multiple malware into a single vector and used malvertising techniques to lure their victims into running their payloads. This attack wave highlights the presence of more peculiar pieces of code, including unconventional malware loader services, utilized by different threat actors. It also emphasizes the need for increased cybersecurity awareness and the importance of using legitimate software to avoid falling prey to such attacks.
In conclusion, the NullMixer operation has continued to evolve and target tech-savvy users through malicious video tutorials and social engineering techniques. The latest campaign revealed Italy as the first European target hit, which is of particular interest given the recent spike in cyber attacks against the country. The data obtained from the investigation has been shared with local authorities and the national CSIRT.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1189 | Drive-by Compromise | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1082 | System Information Discovery |
| T1083 | File and Directory Discovery | |
| Collection | T1005 | Data from Local System |
| T1119 | Automated Collection | |
| Command and Control | T1071 | Application Layer Protocol |
| T1219 | Remote Access Software |
References:
The following reports contain further technical details:
https://securityaffairs.com/144092/malware/maas-threats-delivered-through-nullmixer-malware.html
[/emaillocker]