Cyble – Phishing Site Made By Microsoft Crypto Wallet Spreads Infostealer

[ad_1]

Luca Stealer is making waves in the cyber threat landscape

New product launches generate excitement and excitement among consumers, who eagerly anticipate the latest innovations and technological advancements. However, this excitement also attracts malicious intentions.

Threat Actors (TAs) often take advantage of the hype surrounding new product releases to carry out their devious schemes. These cybercriminals create deceptive phishing sites that pose as legitimate platforms, seeking to compromise users’ security and privacy. Through these scam websites, TAs deliver malware payloads disguised as genuine applications, leading to potentially serious consequences for unsuspecting users.

Cyble Research and Intelligence Labs (CRIL) recently discovered a phishing website with the URL “hxxps[:]//microsoft-en[.]com/cryptowallet/”, which impersonates the legitimate Microsoft Crypto Wallet platform. The main victims targeted by this fraudulent site are cryptocurrency enthusiasts. The site uses a clever disguise, tricking users into downloading an executable file that purports to represent the official Crypto Wallet.

Unfortunately, under the guise of offering a cutting-edge cryptocurrency solution, this deceptive website harbors a malicious InfoStealer named “Luca Stealer”. The main goal of Luca Stealer is to secretly collect sensitive information and personal data from unsuspecting users.

The figure below shows the Microsoft Crypto Wallet phishing site.

Figure 1 – Phishing Site

Several months ago, news surfaced about Microsoft’s plans to develop a Crypto Wallet exclusively for its Edge browser. In light of this development, a disturbing phishing site shown in Figure 1 caught our attention.

Although the exact motives behind the creation of this phishing site remain unclear, it appears that a threat actor (TA) could exploit the information to carry out malicious attacks.

A notable detail on the phishing site is the reference to a beta version of the Crypto Wallet app. This mention further reinforces the possibility that the TA is taking advantage of the development of Microsoft’s Crypto Wallet to lure users into their trap. The attackers aim to trick users into thinking they are accessing a genuine platform by impersonating a legitimate source and referencing the beta version.

Analysis

The file downloaded from this site (SHA256:480cea45f9c10159ef76555a0b86c25b232952b5cbc6da2862ff4b8cbb2943c1) is a 64-bit executable.

The figure below shows the details of the file.

Figure 2 – File Details

Through our investigation, we identified the executable as Luca Stealer. This determination was primarily based on the existence of a significant number of identical strings present in both the suspect executable and the source code known to Luca Stealer. This malware is designed using the Rust programming language, and it first surfaced on cyber crime forums in 2022.

Additionally, our previous blog shed light on Luca Stealer’s source code, which was openly shared and made available on a cybercrime forum.

The figure below clearly illustrates the shared strings that contributed to our identification process.

Figure 3 – Common strings

Luca Stealer has gained increasing popularity within cybercrime forums due to its open source nature and development in Rust. As a result, several TAs have joined forces to improve its functionality and optimize its performance.

Notably, the source code of this malware has been observed on various platforms with GitHub and TOR being prominent hosts. This large-scale distribution ensures that the code remains easily accessible to a wide range of potential tech helpers.

The availability of source code on these platforms facilitates modifications and customizations, allowing TAs to create customized versions of the malware according to their nefarious goals.

Figure 4 – Hosted on different platforms

On closer examination, a significant update of this thief revealed the implementation of two remarkable techniques – Clipper and AntiVM.

The introduction of Clippers marked a concerning development as it allows TAs to intercept and manipulate cryptocurrency addresses during transactions. Through this malicious maneuver, funds intended for a recipient are diverted to the attacker’s wallet, resulting in significant financial loss for the victim.

What sets this Clipper apart is its versatility. Although its main objective is cryptocurrency theft, it does not limit its targets to cryptocurrencies alone. Instead, it is also expanding its reach to target IBANs (international bank account numbers). In doing so, the Clipper expands its potential victims to include those engaged in traditional banking transactions, amplifying the risks for a wider range of users.

The Clipper’s cryptocurrency target scope is broad, including popular cryptocurrencies such as XMR, BNB, TRX, ETH, BTC, DOGE, BCH, LTC, DASH, XRP, ADA, TON, NEO, ETC, SOL, ZEC, ALGO, and XLM. By focusing on these high-value cryptocurrencies, attackers aim to maximize their illicit gains and capitalize on the widespread use and investment in these digital assets.

AntiVM is a defense evasion technique using which TAs can prevent malware from running in a virtualized environment. We observed an additional AntiVM technique in this thief, which distinguishes it from the old binary version.

This variant of Luca stealer now checks the system temperature using a WMI query, specifically using the “SELECT * FROM MSAcpi_ThermalZoneTemperature” command.

Most VMs return an error when running the “SELECT * FROM MSAcpi_ThermalZoneTemperature” query. Therefore, the malware uses this strategy to skip running in virtualized environments. This behavior assumes that the absence of valid temperature data or the occurrence of errors indicates that the system is running in a virtualized environment. Therefore, the malware tries to remain undetected and avoid potential security measures that might be triggered in virtual machine setups.

This technique has been used in the past by malware strains such as GravityRAT.

The figure below illustrates the WMI request used by the thief.

Figure 5 – WMI query

This thief targets the following cold crypto wallets:

AtomicWalletExodusJaxxWalletElectrumByteCoin

This thief variant targets the following browsers.

EdgeChedot (Chedot)Elements BrowserTorchOperaChromeChrome CanaryEpic Privacy BrowserUC BrowserOpera Stable7starChrome SxSChromeUranOpera GXAmigoGoogle ChromeKometaCozMediaChromePlusBraveCocCoc BrowserOrbitumVivaldiMapple StudioCentBrowserDragon (Comodo Dragon)SputnikAtomIridiumSleipnir 5CitrioWooGambleQip Surf3 60brow ser

Track the thief targets browser extensions.

EOS AuthenticatorNorton Password ManagerSolletLeaf WalletBitwardenAvira Password ManagerICONexCyano WalletKeePassXCTrezor Password ManagerKHCCyano Wallet ProDashlaneMetaMaskTezBoxNabox Wallet1PasswordTronLinkByonePolymesh WalletNordPassBinanceChainOneKeyNifty WalletKeeperCoin98DAppPlayLiquality WalletRoboFormiWalletBitClipMath Wallet LastPassWombatS Teem KeychainCoinbase WalletBrowserPassMEW CXNash ExtensionClover WalletMYKINeoLineClient Hycon LiteYoroiSplikityTerra StationZilPayGuardaCommonKeyKeplrSolletEQUAL WalletZoho VaultNorton Password ManagerICONexBitApp Wallet

To retrieve the IP of the infected system, this thief makes a GET request to hxxps://myip[.]ch. The figure below shows network activity.

Figure 6 – GET request

Once it gathers the targeted information, it compresses the data to streamline its transfer process. To discreetly send the stolen data, the malware uses a Telegram bot, using the Telegram messaging platform as a secret communication channel. Moreover, it sends chat messages containing statistical information about the stolen data. Although simple, this feature provides the attacker with real-time updates on the amount and nature of compromised data.

Conclusion

Luca Stealer shares several key characteristics typical of InfoStealers, but what sets him apart is his particular focus on targeting data associated with cryptocurrency wallets and password management software. This refined focus highlights the malicious intent to exploit the growing popularity and value of cryptocurrencies, as well as the potential for acquiring sensitive login credentials.

The fact that Luca Stealer’s source code is open source further compounds the concern. As more TAs gain access to the codebase, the potential for malware customization and adaptation increases dramatically. This accessibility allows cybercriminals to create unique variants and modify the behavior of Luca Stealer according to their specific goals. Therefore, we can expect a continued increase in the number of rogue binaries targeting users.

Our recommendations

We have listed some of the essential cybersecurity best practices that create the first line of control against attackers. We recommend our readers to follow the suggestions below:

Avoid downloading pirated software from warez/torrent websites. The “Hack Tool” present on sites like YouTube, torrent sites etc. usually contains such malware. Use strong passwords and enforce multi-factor authentication where possible. Activate the automatic software update function on your computer, mobile and other connected devices. Use reputable antivirus and internet security software on your connected devices, including PCs, laptops, and mobiles. Refrain from opening untrustworthy links and attachments without first verifying their authenticity. Educate employees on protection against threats such as phishing/untrusted URLs. Block URLs that could be used to spread malware, eg Torrent/Warez. Monitor the beacon at the network level to block data exfiltration by malware or TAs. MITER ATT&CK Techniques Tactic Technique ID Technique Name Initial Access T1566 Phishing Execution T1204 User Execution Defense Evasion T1497 Virtualization/Sandbox Evasion Credential Access T1555 T1539 T1552 1007 T1614 T1120 Software Discovery Process Discovery System Time Discovery System Service Discovery Device Location Discovery Command and ControlT1571 T1095 Non-Standard Port Non-Application Layer Protocol ExfiltrationT1041 C2 Channel Exfiltration Indicators of Compromise (IoC): Indicators Indicator Type Description hxxps[:]//microsoft-fr[.]com/cryptowallet/cryptowalletinstaller[.]exe hxxps[:]//microsoft-fr[.]com/cryptowallet/URL Phishing Site 2753fea9125455e452e1951295158bc5 4238700742f6540119fc40f8f001fa1b5da99425 480cea45f9c10159ef76555a0b86c25b23295 2b 5cbc6da2862ff4b8cbb2943c1MD5 SHA1 SHA256Luca Stealer

Sources

1/ https://Google.com/

2/ https://blog.cyble.com/2023/07/21/fabricated-microsoft-crypto-wallet-phishing-site-spreads-infostealer/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts