Since the first Nymaim case was detected in 2013, over 2.8 million cases of infection have been recorded using the“killchain” mechanism and evasion techniques. In the first half of 2016, ESET again observed a significant increase in Nymaim detections.
Mainly affecting Poland (54% of detections ) , Germany (16%), and the United States (12%), the renewed variant was detected as Win32/TrojanDownloader.Nymaim.BA , making its reappearance as a full-fledged spearphishing campaign with a malicious attachment (Word .doc) that “deceptively” contains Marcos. The approach used to bypass Microsoft Word ’s default security settings through social engineering mechanisms is quite convincing in English versions of MS Word.
" With advanced evasion techniques , anti- VM , anti-debugging and control flow capabilities , this two -stage downloader , which carries ransomware as a final payload , has now evolved and is being used to deliver spyware," says Cassius de Oliveira Puodzius, Security Researcher at ESET Latinoamerica.
In April, this version was joined by hybridvariant a of Nymaim and Gozi , targeting financial institutions in North America, and has also spread to Latin America, primarily Brazil. This variant has given cybercriminals the ability to remotely access compromised computers , rather than having the usual effects of encrypting files or locking them down .
Due to the similarities between targets found in countries with high and low detection rates, we can be relatively confident that financial institutions remainatthe center of this campaign.
" The full documentation of this threat is still in progress. However, if you suspect that your computer or network has been compromised, we recommend that you check whether the IP addresses and URLs , found in the fullarticle , are not in your firewall and proxy login details . In any case, a prevention strategy against the threat can be implemented by blacklisting the IPs that have come into contact with this malware in your firewall and the URLs in your proxy, provided that your network supports this type of filtering," concludes Puodzius .
The full analysis is available on ESET 's informative blog , Welivesecurity.com.
