EXECUTIVE SUMMARY
Researchers have uncovered a malvertising campaign that entices users into downloading malicious installers for popular software like Google Chrome and Microsoft Teams. These installers deliver a backdoor identified as Oyster, also known as Broomstick. Once executed, the backdoor conducts enumeration commands indicative of manual intervention and deploys additional malicious payloads. The threat actors used typo-squatted websites to masquerade as legitimate software download pages, tricking users into downloading and executing their malicious installers.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have uncovered a malvertising campaign that entices users into downloading malicious installers for popular software like Google Chrome and Microsoft Teams. These installers deliver a backdoor identified as Oyster, also known as Broomstick. Once executed, the backdoor conducts enumeration commands indicative of manual intervention and deploys additional malicious payloads. The threat actors used typo-squatted websites to masquerade as legitimate software download pages, tricking users into downloading and executing their malicious installers.[emaillocker id="1283"]
Upon execution, the malicious installer, such as MSTeamsSetup_c_l_.exe, drops two binaries into the system's Temp directory: CleanUp30.dll and a legitimate Microsoft Teams installer. The DLL creates a mutex to ensure only one instance runs and establishes a scheduled task to execute the DLL periodically. The DLL decodes hard-coded command-and-control (C2) addresses using a custom obfuscation technique and gathers system information like domain, username, computer name, and OS details. This information is then encoded and sent to the C2 servers via HTTP POST requests. Additionally, in some incidents, a PowerShell script was observed creating a persistent shortcut that re-executes the DLL upon user login.
This malvertising campaign highlights the methods employed by threat actors to exploit user trust and deliver malware. By using typo-squatted websites and valid digital certificates, the attackers effectively disguised their malicious software as legitimate installers. The Oyster backdoor's advanced techniques for persistence, system fingerprinting, and C2 communication underscore the importance of vigilance and robust security measures to protect against such threats. Users should exercise caution when downloading software and verify the authenticity of websites and installers to avoid falling victim to similar attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Resource Development | T1583 | Acquire Infrastructure |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1497 | Virtualization/Sandbox Evasion |
| Collection | T1005 | Data from Local System |
| Command and Control | T1132 | Data Encoding |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/06/oyster-backdoor-spreading-via.html
[/emaillocker]