HomeSecurityLucifer: The powerful malware that targets Windows computers!

Lucifer: The powerful malware that targets Windows computers!

A new powerful encryption and DDoS, “Lucifer,” is exploiting critical vulnerabilities to infect Windows computers. According to Palo Alto Networks’ Unit 42, Lucifer is part of an active campaign targeting Windows hosts and using a variety of exploits. The malware’s operators have dubbed their creation “Satan DDoS.” However, because the Satan Ransomware exists elsewhere, Palo Alto has given it a different name.

Lucifer malware

In a blog post, researchers Ken Hsu, Durgesh Sangvikar, Zhibin Zhang, and Chris Navarrete reported that the latest variant of Lucifer, v.2, was discovered on May 29, in an attempt to exploit CVE-2019-9081, a deserialization bug in the Laravel Framework, which can be used in remote code execution. After a more detailed examination, it turned out that this is one of many vulnerabilities exploited by the malware, along with CVE-2014-6287, CVE-2018-1000861, CVE-2017-10271, ThinkPHP RCE vulnerabilities (CVE-2018-20062), CVE-2018-7600, CVE-2017-9791, CVE-2019-9081, CVE-2017-0144, CVE-2017-0145 and CVE-2017-8464, among others.

malware

Patches are available for all security flaws , but on unpatched hosts, attacks that exploit these flaws are often trivial to exploit, and code execution for cryptocurrency mining is one of the ultimate goals. Lucifer is considered a powerful hybrid malware, which has the ability to encrypt and exploit infected computers to perform DDoS attacks. In addition, the malware searches for open TCP ports 135 (RPC) and 1433 (MSSQL) to find targets and performs credential spoofing attacks to gain access. It can infect its targets via IPC, WMI, SMB, and FTP via brute-force attacks, as well as via MSSQL, RPC, and network shares. Once Lucifer is installed on an infected device, it “drops” XMRig, a program used to mine the Monero (XMR) cryptocurrency. It also connects to a command-and-control (C2) server to receive commands, transfer data from the compromised system, and inform its operators about the status of the Monero cryptocurrency miner. To spread, Lucifer uses various vulnerabilities and brute-force attacks, attempting to compromise more Windows hosts connected to the initial point of infection. The malware also tampers with the Windows registry to schedule itself as a startup task. It also attempts to evade detection by checking for the presence of sandboxes or virtual machines.


The first wave of attacks using Lucifer v.1 was detected on June 10. A day later, the malware was upgraded to version 2, which was particularly destructive for the targeted devices. Researchers recommend that users apply the required patches and updates to the affected software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS