Acronis Threat Research Unit identified the Shadow Vector malware campaign targeting Colombian users through malicious SVG files and spear-phishing emails impersonating legal institutions. The campaign deploys multistage payloads including AsyncRAT and RemcosRAT using DLL side loading and driver-based privilege escalation, with advanced obfuscation and anti-analysis techniques. #ShadowVector #AsyncRAT #RemcosRAT #KatzLoader
Keypoints
- The Shadow Vector campaign uses malicious SVG files embedded in spear-phishing emails impersonating Colombian judicial institutions to deliver malware.
- Payloads include AsyncRAT and RemcosRAT, executed via DLL side loading and driver-based kernel privilege escalation using vulnerable drivers.
- The campaign employs multistage infection chains with obfuscated .NET loaders, UAC bypasses, process hollowing, and persistence mechanisms.
- Payloads have advanced anti-analysis and anti-VM techniques, including custom PE header manipulation and environment checks to evade detection.
- The attack harvests keystrokes, credentials, browser data, and cryptocurrency wallet information, with potential expansion into destructive operations like ransomware.
- Latest iterations deploy Katz Loader-based modular loaders fetched at runtime, using public hosting services like Bitbucket and Paste.ee.
- The presence of Portuguese language strings suggests code reuse or collaboration with Brazilian threat actors in Latin America.
MITRE Techniques
- [T1193] Spearphishing Attachment – Used spear-phishing emails impersonating Colombian judicial institutions with malicious SVG file attachments (‘…Phishing email impersonating Colombia’s labor court uses a password-protected malicious SVG lure…’).
- [T1027.011] Obfuscated Files or Information: Steganography – Hides payloads as Base64 content within text or image files retrieved from the Internet Archive (‘…with payloads sometimes hidden as Base64 within text or image files retrieved from the Internet Archive’).
- [T1574.002] DLL Side-Loading – Executes malware by loading malicious DLLs via side loading with legitimate executables like vcredist.exe or CiscoSparkLauncher.dll (‘…the attack uses DLL side loading…’).
- [T1055.012] Process Hollowing – Injects malicious code into legitimate processes such as AddInProcess32.exe to evade detection (‘…performs process hollowing to inject and execute the malicious module…’).
- [T1548.002] Abuse Elevation Control Mechanism: Bypass User Account Control – Uses cmstp.exe for UAC bypass (‘…optional UAC bypass using cmstp.exe…’).
- [T1543.003] Create or Modify System Process: Windows Service – Installs vulnerable drivers as kernel-mode services to escalate privileges (‘…both vulnerable drivers are launched as kernel-mode services…’).
- [T1036.005] Masquerading: Match Legitimate Name or Location – Uses legitimate filenames and folder paths like CiscoSparkLauncher.dll and vcredist.exe to disguise malicious components (‘…the executable often uses names like vcredist.exe to appear harmless…’).
- [T1083] File and Directory Discovery – Checks for browser extensions and cryptocurrency wallets by examining specific folders (‘…the malware checks for the presence of cryptocurrency wallets and specific browser extensions by inspecting designated folders’).
- [T1566.001] Phishing: Spearphishing Link – SVG files contain embedded links redirecting to payloads hosted on public file-sharing platforms (‘…SVG files…redirect users to archives hosted on public file-sharing platforms such as Bitbucket, Discord CDN and YDRAY’).
Indicators of Compromise
- [File Hash] SHA256 hash of malicious SVG file – 64e971f0fed4da9d71cd742db56f73b6f7da8fec3b8aebd17306e8e0d4f1d29d4
- [File Name] Decoy executables and DLLs – vcredist.exe, CiscoSparkLauncher.dll, VERSION.dll, AddInProcess32.exe, svchost.exe
- [Domains] Command and control servers – asynk02.duckdns.org
- [Email] Phishing email sender aliases – ‘TheMrHacker’, ‘Envio’
- [File Hash] Other payload hashes – 0e5a768a611a4d0ed7cb984b2ee790ad4, and 1 more hash