[ad_1]
A new malware campaign has been discovered targeting cryptocurrencies, non-fungible tokens (NFTs) and DeFi aficionados through Discord channels to deploy an encryptor named ‘Babadeda’ capable of bypassing antivirus solutions and organizing various attacks.
“[T]its malware installer has been used in various recent campaigns to deliver LockBit information thieves, RATs and even ransomware, ”Morphisec researchers said in a report released this week. Malware distribution attacks reportedly began in May 2021.
Encryptors are a type of software used by cybercriminals that can encrypt, mask, and manipulate malicious code in such a way that it appears seemingly harmless and makes it harder for security programs to detect – a holy grail for malware authors. .
The infiltrations observed by Morphisec involved the threat actor sending decoy messages to potential users on Discord channels related to blockchain-based games such as Mines of Dalarnia, urging them to download an app. If a victim clicks on a URL embedded in the message, the individual is taken to a phishing domain designed to resemble the legitimate game website and includes a link to a malicious installer containing the Babadeda encryptor.
Upon execution, the installer triggers an infection sequence that decodes and loads the encrypted payload, in this case BitRAT and Remcos, to harvest valuable information.
Morphisec attributed the attacks to a threat actor from a Russian-speaking country, due to the Russian-language text posted on one of the decoy sites. Up to 84 malicious domains, created between July 24, 2021 and November 17, 2021, have been identified to date.
“Targeting cryptocurrency users through trusted attack vectors gives its distributors an increasingly rapid selection of potential victims,” the researchers said. “Once on a victim’s machine, pretending to be a known application with complex obfuscation also means that anyone relying on signature-based malware has no way of knowing Babadeda is on their system. machine – or prevent it from running. “
|
Sources 2/ https://thehackernews.com/2021/11/crypto-hackers-using-babadeda-crypter.html The mention sources can contact us to remove/changing this article |
[ad_2]