HomeSecurityBlackWater Malware: Pretends to be a file with information about the coronavirus

BlackWater Malware: Pretends to be a file with information about the coronavirus

A new malware called BlackWater pretends to be information about the COVID-19 coronavirus while abusing Cloudflare Workers as an interface to the malware's command and control (C2) server.

Cloudflare Workers are JavaScript programs that run directly from the Cloudflare edge, so they can interact with remote web clients. These Workers can be used to modify the output of a website behind Cloudflare, disable Cloudflare features, or even run as standalone JavaScript.

For example, a Cloudflare Worker can be created to search for text in a web server output and replace words in it, or simply output data back to a web client.

BlackWater uses Cloudflare Workers as a C2 interface

Recently, MalwareHunterTeam discovered a distributed RAR file pretending to be a file with information about the Coronavirus (COVID-19) called “Important – COVID-19.rar”.

BlackWater Malware: Pretends to be a file with information about the coronavirus

It is currently unknown how the file is distributed, but it is likely via phishingemails.

Inside this RAR file is a file titled “Important – COVID-19.rar” that uses a Word icon. Unfortunately, since Microsoft hides file extensions by default, many will simply see this file as a Word rather than an executable and will be more likely to open it.

While victims are reading the COVID-19 document, the malware also extracts the file %UserProfile%\AppData\Local\SQL Library\bin\version 5.0\sqltuner.exe.

This is where things get a little interesting as the malware is launched using a command line that causes the BlackWater malware to connect to a Cloudflare Worker that acts as a command and control server.

If you visit this website directly, users will see the following “HellCat” image.

SentinelLabs head Vitali Kremez told BleepingComputer that this worker is the front end of a ReactJS Strapi application that acts as a command and control server.

Kremez said this C2 will respond with an encoded JSON string that may contain commands to execute when the malware connects to it with the correct authentication parameters.

When asked why they used a Cloudflare Worker instead of connecting online to the C2, Kremez felt it was more difficult for software to block IP traffic without blocking the entire Cloudflare Worker infrastructure.

While there is still much to learn about this new malware and how it works, it provides an interesting look at how malware developers are using legitimate cloud in novel ways.

By using CloudWorkers, traffic to malware command and control servers becomes more difficult to block, and malware operation can be easily scaled as needed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS