EXECUTIVE SUMMARY
Void Arachne, a newly identified threat actor group, has launched a campaign targeting Chinese-speaking users. The group's operation involves the distribution of malicious MSI files that contain legitimate software installers for various AI applications, popular software, and VPNs. These MSI files are distributed through SEO poisoning and shared across several Chinese-language-themed Telegram channels. During the installation process, a Winos backdoor is also installed, posing a significant risk of full system compromise.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Void Arachne, a newly identified threat actor group, has launched a campaign targeting Chinese-speaking users. The group's operation involves the distribution of malicious MSI files that contain legitimate software installers for various AI applications, popular software, and VPNs. These MSI files are distributed through SEO poisoning and shared across several Chinese-language-themed Telegram channels. During the installation process, a Winos backdoor is also installed, posing a significant risk of full system compromise.[emaillocker id="1283"]
The malicious MSI files in this campaign are bundled with legitimate software, including deepfake obscenity-generating AI software, voice-and-face-swapping AI software, and Chinese-marketed VPNs such as LetsVPN and QuickVPN. These installers perform multiple tasks without the user's knowledge, including creating scheduled tasks, configuring firewall rules, and establishing port forwarding to the attacker's C&C server. The Winos 4.0 implant, written in C++, is the final payload, equipped with capabilities for remote control, file management, DDoS attacks, webcam control, and more. It communicates with its C&C server using an encryption algorithm and stores plugins in the Windows Registry to perform various malicious activities.
Void Arachne's campaign exploits the public interest in AI technologies and VPNs to distribute malware through SEO poisoning and social media platforms like Telegram. The group's use of AI-generated deepfake obscenity and voice-altering technologies raises concerns about potential misuse, including virtual kidnapping schemes. It is crucial for individuals and organizations to download software only from trusted sources and to be vigilant about the risks associated with MSI files. Implementing comprehensive security solutions can help detect, respond to, and mitigate such threats effectively, improving overall cybersecurity posture and resilience.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1199 | Trusted Relationship |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1012 | Query Registry |
| T1082 | System Information Discovery | |
| Collection | T1005 | Data from Local System |
| T1113 | Screen Capture | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| T1048 | Exfiltration Over Alternative Protocol | |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html
[/emaillocker]