Threat Advisory

Verblecon: Sophisticated New Loader Used in Low-level Attacks

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

Unknown attacker may not be aware of the potential capabilities of the malware they are utilising because they are using a sophisticated and strong new malware loader in very simple and low-reward attacks. The Trojan.Verblecon malware is being utilised in attacks that seem to have as their ultimate objective the installation of bitcoin miners on compromised machines. There are also hints that the attacker might potentially be planning to steal Discord access tokens.

The malware is loaded as a polymorphic JAR file on the server. The malware examines its command-line inputs after being launched. It runs several commands to get a list of active processes. Then it makes a copy of itself and makes a file to be used as a loadpoint. Then it attempts to connect to various URLs on a regular basis and begins communicating with the decoded URL by transmitting information about the infected computer and downloading the obfuscated payload. The primary function is to execute and download a binary blob from the URL. The blob is decrypted alongside *.bin artefacts from the same host. After being cached on the local filesystem, the downloaded blob is then injected for execution. Instead of using the standard injection APIs, the injection is carried out via com.sun.jna. The embedded URL leading to a cryptocurrency miner configuration file is included in the final payload.

The evidence discovered on victim networks seems to suggest that the attacker's intention was to set up cryptocurrency mining software on the victim computers. Given the amount of effort it would have taken to create such sophisticated malware, this would seem to be an attack target with a low reward. There are also hints that the attacker might be obtaining Discord tokens and using them to promote videogame applications that have been infected with malware.

 

Threat Profile:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
Defense Evasion T1112 Modify Registry
T1107 Indicator Removal
T1027 Obfuscated Files or Information
Discovery T1082 System Information Discovery
Collection T1005 Data from Local System
Exfiltration T1041 Exfiltration Over Command-and-Control Channel
Impact T1496 Resource Hijacking

 

References:

The following reports contain further technical details:

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/verblecon-sophisticated-malware-cryptocurrency-mining-discord

[/emaillocker]
crossmenu