Infostealer malware disguised as legal and copyright infringement documents is actively distributed in Korea via email attachments, employing DLL Side-Loading and double extension techniques to evade detection. The malware targets sensitive user information, exfiltrating data related to emails, FTP, banking, and browser credentials to remote servers. #Rhadamanthys #Infostealer #DLLSideLoading #DoubleExtension
Keypoints
- Infostealer malware disguised as documents on legal responsibilities and copyright infringement is distributed through email attachment links in Korea.
- Two main execution methods are used: DLL Side-Loading, involving malicious DLLs loaded by legitimate EXE files, and double extension disguising EXE files as document files.
- The DLL Side-Loading method uses legitimate PDF Reader EXE and malicious DLLs to inject Rhadamanthys Infostealer into system processes for data exfiltration.
- The double extension method uses EXE files disguised as PDFs and a text file prompting execution, then uses PowerShell commands to kill security-related processes.
- The malware targets sensitive information including email, FTP, online banking credentials, browser accounts, and captures screens, sending data to threat actors’ servers.
- Similar Infostealer campaigns using copyright infringement-themed file names have been detected in Thailand, Hungary, Portugal, Greece, and Japan.
- Users are advised to avoid executing suspicious email or messenger files, as even legitimate programs may load malicious DLLs leading to compromise.
MITRE Techniques
- [T1073] DLL Side-Loading – Loaded malicious DLLs alongside legitimate executables to execute Rhadamanthys Infostealer (“malicious DLL is loaded when the legitimate application is run”).
- [T1059] Command and Scripting Interpreter – Used PowerShell commands to terminate security tools and avoid detection (“Infostealer uses a Powershell command to terminate a specific process”).
- [T1055] Process Injection – Injected malicious code into legitimate Windows system processes such as openwith.exe and rundll32.exe (“Rhadamanthys performs DLL injection into legitimate Windows system programs”).
- [T1204] User Execution – Trick users into executing disguised files with double extensions and misleading file names (“EXE file is disguised as a PDF document using a double extension”).
- [T1566] Phishing – Distributed malware via email attachments with links prompting download of supposed copyright infringement evidence (“distributed through links in email attachments, email instructs … to download the evidence”).
Indicators of Compromise
- [File Hash] Examples of malware file MD5 hashes – 64a145f3716c4fae76389ced81013e28, ca58a723609057048c97ebd8f9b4d36f
- [URL] Malicious distribution links – hxxps://tr[.]ee/3FKnsw, hxxps://laurayoung2169944-dot-yamm-track.appspot[.]com/2gwdQgyj0E2vzqvbGg2Q8Vfawz52qe38tVH-Y92ZoVgBqJibClgEzOCbYyqGbTJh0dKhw8GQbFcFesz7f9zrLq-2V-eP1KMh9AEWIYxXvJBaYeQMZELdDvNm3D-jXjmCZhpzvekp6k6wRmVhQAy8E8tvBKAmido8oujb3kXgIEfYHLKv2LcSBPU3qzwd3tG0yoQroSnpBWvxoJ0Cigir-WRpFZtmNqF9GzWiYvcbQYCAFW112o2ZfGIvFBZS2YBmvm5iJcYtbCXPbhF_PffE2uiWA
- [File Name] Suspicious distributed compressed file names – “Definite evidence helps to confirm the criminal behavior.zip”, “Evidence and Detailed Information on Copyright Infringement.zip”
Read more: https://asec.ahnlab.com/en/88544/