Threat Advisory

New Threats delivered through NullMixer

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

During March 2023, an ongoing malware operation was discovered that targeted more than 8,000 victims in North America, Italy, and France. The attackers utilized SEO poisoning and social engineering techniques to lure tech-savvy users, particularly IT personnel, into installing backdoored, cracked versions of well-known PC maintenance software such as "EaseUS Partition Master" and "Driver Easy Pro." The malicious campaign was traced back to a worldwide malware operation known as NullMixer, which is designed to provide infection services to criminal threat actors.

The attack was initiated through a series of YouTube videos promoting the cracked versions of the software, with one of them featuring a masked hacker explaining how to use the crack linked in the video description. The attackers used Bitly shortener and a BlogSpot account to protect the malicious code, which was then stored in an encrypted zip archive hosted on Mega.nz. The payload delivered by NullMixer remained substantially the same, consisting of a WinRAR executable archive containing multiple binaries that were auto launched on click. The malware delivered during this attack included two unknown loaders entering the MaaS and PPI businesses, namely CrashedLoader and Koi, and a controversial, potentially North-Korean linked piece of malware.

During the investigation, it was discovered that the attackers were evolving their social engineering techniques by producing YouTube videos that contained instructions to download and run the backdoored pirate software. The attackers packed multiple malware into a single vector and used malvertising techniques to lure their victims into running their payloads. This attack wave highlights the presence of more peculiar pieces of code, including unconventional malware loader services, utilized by different threat actors. It also emphasizes the need for increased cybersecurity awareness and the importance of using legitimate software to avoid falling prey to such attacks.

In conclusion, the NullMixer operation has continued to evolve and target tech-savvy users through malicious video tutorials and social engineering techniques. The latest campaign revealed Italy as the first European target hit, which is of particular interest given the recent spike in cyber attacks against the country. The data obtained from the investigation has been shared with local authorities and the national CSIRT.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1189 Drive-by Compromise
Execution T1059 Command and Scripting Interpreter
T1204 User Execution
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
Discovery T1082 System Information Discovery
T1083 File and Directory Discovery
Collection T1005 Data from Local System
T1119 Automated Collection
Command and Control T1071 Application Layer Protocol
T1219 Remote Access Software

 

References:

The following reports contain further technical details:

https://securityaffairs.com/144092/malware/maas-threats-delivered-through-nullmixer-malware.html

[/emaillocker]
crossmenu