Summary:
In recent threat research, the focus has been on the evolving tactics of cyber threat actors behind malware families RedLine and Vidar. Initially associated with spear-phishing scams, these actors have now shifted towards distributing ransomware using the same delivery techniques employed for info stealers. An intriguing aspect of their activities involves the misuse of Extended Validation (EV) code signing certificates, typically associated with high levels of security. Despite industry efforts to enhance certificate security, these threat actors managed to abuse EV certificates extensively.[/subscribe_to_unlock_form]
Summary:
In recent threat research, the focus has been on the evolving tactics of cyber threat actors behind malware families RedLine and Vidar. Initially associated with spear-phishing scams, these actors have now shifted towards distributing ransomware using the same delivery techniques employed for info stealers. An intriguing aspect of their activities involves the misuse of Extended Validation (EV) code signing certificates, typically associated with high levels of security. Despite industry efforts to enhance certificate security, these threat actors managed to abuse EV certificates extensively.[emaillocker id="1283"]

Execution Flow
The cyber adversaries orchestrating RedLine and Vidar campaigns have honed their methods to deceive victims. Their tactics include employing urgency-inducing phrases in spear-phishing emails related to health and hotel accommodations, using double file extensions to disguise executable files as harmless documents, and employing LNK files to bypass detection mechanisms. Even Google Drive's security protocols have not deterred them from using the platform to transfer malicious files. In a specific case, they pivoted from distributing info stealers to delivering ransomware, capitalizing on a fake TripAdvisor complaint email attachment. This attachment, masquerading as a benign PDF with a double extension, executed JavaScript files, leading to the deployment of ransomware. Importantly, while the info stealers were signed with EV certificates, the ransomware payload was not, suggesting a division of labor within the threat actor group.
The threat landscape continually evolves, with cybercriminals adapting and optimizing their techniques. The case of RedLine and Vidar highlights the adaptability of threat actors who use spear-phishing tactics. They exploit trusted security measures like EV code signing certificates and raise questions about the effectiveness of certificate revocation. To combat such multifunctional threats, organizations and individuals must adopt proactive security measures, including early threat detection and robust attack surface protection. Avoiding downloads from unverified sources and implementing multilayered protection systems is paramount in safeguarding against evolving cyber threats.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/09/cybercriminals-combine-phishing-and-ev.html
[/emaillocker]