HomeSecurityIcedID banking trojan: New variant exploits COVID-19!

IcedID banking trojan: New variant exploits COVID-19!

Researchers at Juniper Threat Labs have discovered a new variant of the IcedID banking trojan used in attacks that exploit COVID-19. The new variant uses a process called steganography to infect potential victims, while also exhibiting capabilities that allow it to be undetectable. Researchers have identified a COVID-19-themed spam campaign targeting users in the US, with the new variant being able to monitor victims’ online activity. The emails sent by the campaigncontain attachments that, when opened by a user, download the IcedID banking trojan.

IcedID banking trojan: New variant exploits COVID-19!

The IcedID banking trojan first appeared in 2017 and has capabilities similar to other banking threats such as Gozi, Zeus and Dridex malware. IBM X-Force experts who first analyzed this trojan noted that it does not borrow code from other banking malware, but it can be compared to them in several characteristics, including launching attacks from the browser and stealing financial information from victims. The campaign recently detected by Juniper Threat Labs researchers aimed to steal credentials and credit card data from Amazon.com, American Express, AT&T, Bank of America, Capital One, Chase, Discover, eBay, E-Trade, JP Morgan, Charles Schwab, T-Mobile, USAA, Verizon Wireless, Wells Fargo and other leading companies and businesses. This campaign exploits the COVID-19 pandemic by using keywords, such as COVID-19 and FMLA, in email and attachment names. Unlike previous variants, the latest variant of the trojan injects itself into msiexec.exe to handle browser traffic and uses steganography to download its modules and configurations.

Upon opening a malicious document, it “drops” a binary that in turn brings a loader . The loader retrieves another loader that downloads a third-stage payload, which opens an embedded binary in its resource and executes it. Once opened, it downloads the main module of the IcedID banking trojan as a PNG file from the link https://cucumberz99[.]club/image?id={01XXXXXXXXXXXXXXXXXXXXX}. The researchers reported that the decrypted code is not a complete PE image, as it does not contain any header. Most of its strings are also encrypted, which makes analysis even more difficult.

IcedID banking trojan: New variant exploits COVID-19!

Once the main module code of IcedID is injected into the msiexec.exe process, it will start connecting to the command-and-control server and waiting for commands. The main function of the malware core is to steal financial data using webinjects. IcedID monitors specific browser process names:

  • Firefox.exe
  • Chrome.exe
  • Iexplore.exe

If the victim opens a browser window, the IcedID malware creates a local proxy listening on 127.0.0.1:56654. connects APIs to browsers and creates a certificate in the %TEMP% folder. Thus, all browser connections are made to msiexec.exe and full control of the browser is achieved. The malware then monitors browser activity related to financial transactions and enters forms on the fly in an attempt to steal a potential victim’s credit card details. Juniper researchers concluded that the IcedID banking trojan is a highly sophisticated malware developed by skilled attackers who are constantly evolving their “arsenal”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS