HomeSecurityHackhound Password Stealer was used in a spying campaign

Hackhound Password Stealer was used in a spying campaign

Security researchers from McAfee came face to face with an exposed web server that was intended to host the C&C servers for various password stealers, which were used to target several companies as part of an industrial espionage campaign.

Hackhound Password Stealer was used in a spying campaign

The mistake that allowed researchers to piece together the pieces was the crook's lack of attention to detail, as he forgot to delete the ZIP package from one of the compromised Web servers used to host several C&C servers.

By examining the files in this ZIP archive and the C&C server source code, McAfee researchers quickly identified the server-side component of the ISR Stealer, a modified version of the Hackhound infostealer, which, in turn, was an ancient piece of malware first detected in 2009.

hackhound-password-stealer-image

Researchers discovered that the crooks used the IRS Stealer malware to create a password stealer capable of stealing login credentials from applications such as Internet Explorer, Firefox, Google Chrome, Opera, Safari, Yahoo Messenger, MSN Messenger, Pidgin, FileZilla, Internet Download Manager, JDownloader, and Trillian.

The crooks distributed this custom password stealer as RAR or Z archives sent via spear-phishing emails to various companies dealing in machine parts.

These RAR and Z files contained executables that would load the password-stealing malicious software. If the victim downloaded the RAR / Z files and executed the EXE file inside, the malware would collect all available passwords and send the data to the C&C server as an HTTP request (request).

The IRS Stealer server-side component would only accept submitted data if the user agent string was "HardCore Software For : Public", specifically for the client-side component. The data would then be stored in a local INI file.

Looking back at the historical data, the McAfee researchers discovered that this campaign had indeed started in January 2016 and that the scammers had compromised various websites where they hosted their C&C servers.

On one of these exposed websites, researchers discovered over ten C&C servers that were receiving data from various victims, which show that the criminals were not targeting only one company, but an entire category of businesses operating in a specific sector of activity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS