In a report published on Saturday (February 16), researchers described a new malware, which they described as "multi-stage malware," that was first detected in August 2018 but was largely ignored at the time due to its rare activity.
When the team of researchers started monitoring the malware, it was only updated once a month. However, since January 2019, the company has seen a noticeable increase in the number of times the malware was updated.
According to Avast, malware is now spreading on a daily basis.
Rietspoof malware
Rietspoof has the ability to infect victims, gain access to infected hosts, and then download other malware strains, depending on the commands it receives from a command & control (C&C) server.
Access is gained by placing a LNK file in the Windows/Startup folder. “This file runs an expanded PE file after boot, to ensure that the executable will run if the machine is restarted,” Avast said.
This is a feature that doesn't go unnoticed, as most antivirus products monitor this type of folder, but Avast says that Rietspoof appears to have legitimate certificates, which allows it to bypass security checks.
Malware has four different stages
The process of infecting a device consists of four different stages. The actual malware enters in the third stage, with the last and final stage being reserved for downloading a more nasty and effective malware.
"We observed that the development of this third stage is evolving rapidly, sometimes running two different branches simultaneously. During our analysis, the communication protocol was modified multiple times and new features were added," Avast said.
Avast described the Rietspoof malware as a “dropper” or “downloader,” which operates similarly to a Trojan and installs other malware strains.
When alone, this feature is limited, according to security researchers. It can download, execute, upload, and delete files, and in an emergency, it can also be deleted.
Avast claims that there are likely more stages of infection that have not yet been discovered.
