Threat Advisory

Oyster Backdoor Spreading Through Trojanized Popular Software Downloads

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have uncovered a malvertising campaign that entices users into downloading malicious installers for popular software like Google Chrome and Microsoft Teams. These installers deliver a backdoor identified as Oyster, also known as Broomstick. Once executed, the backdoor conducts enumeration commands indicative of manual intervention and deploys additional malicious payloads. The threat actors used typo-squatted websites to masquerade as legitimate software download pages, tricking users into downloading and executing their malicious installers.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have uncovered a malvertising campaign that entices users into downloading malicious installers for popular software like Google Chrome and Microsoft Teams. These installers deliver a backdoor identified as Oyster, also known as Broomstick. Once executed, the backdoor conducts enumeration commands indicative of manual intervention and deploys additional malicious payloads. The threat actors used typo-squatted websites to masquerade as legitimate software download pages, tricking users into downloading and executing their malicious installers.[emaillocker id="1283"]

Upon execution, the malicious installer, such as MSTeamsSetup_c_l_.exe, drops two binaries into the system's Temp directory: CleanUp30.dll and a legitimate Microsoft Teams installer. The DLL creates a mutex to ensure only one instance runs and establishes a scheduled task to execute the DLL periodically. The DLL decodes hard-coded command-and-control (C2) addresses using a custom obfuscation technique and gathers system information like domain, username, computer name, and OS details. This information is then encoded and sent to the C2 servers via HTTP POST requests. Additionally, in some incidents, a PowerShell script was observed creating a persistent shortcut that re-executes the DLL upon user login.

This malvertising campaign highlights the methods employed by threat actors to exploit user trust and deliver malware. By using typo-squatted websites and valid digital certificates, the attackers effectively disguised their malicious software as legitimate installers. The Oyster backdoor's advanced techniques for persistence, system fingerprinting, and C2 communication underscore the importance of vigilance and robust security measures to protect against such threats. Users should exercise caution when downloading software and verify the authenticity of websites and installers to avoid falling victim to similar attacks.

THREAT PROFILE:

Tactic Technique Id Technique
Resource Development T1583 Acquire Infrastructure
Execution  T1059 Command and Scripting Interpreter
Defense Evasion T1497 Virtualization/Sandbox Evasion
Collection T1005 Data from Local System
Command and Control T1132 Data Encoding

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/06/oyster-backdoor-spreading-via.html

[/emaillocker]
crossmenu