HomeSecurityGootkit malware: It returns and targets Germany together with REvil!

Gootkit malware: It returns and targets Germany together with REvil!

Gootkit, a trojan that steals information from systems , is making a comeback on the threat landscape after a year of inactivity. This time, it’s not alone, but joining forces with REvil ransomware in a new malicious campaign targeting Germany. Gootkit trojan is a Javascript-based malware that performs various malicious activities, including remote access, keylogging, video recording, email, password theft, and malicious script injection, with the aim of stealing online banking credentials.

In 2019, the hackers who developed Gootkit suffered a data breach after leaving a MongoDB database exposed online. After this breach , it was thought that the hackers had completely stopped their activities. However, they are now making a comeback.

Gootkit malware: It returns and targets Germany together with REvil!

A security researcher known as “The Analyst” told BleepingComputer last week that the Gootkit malware is carrying out attacks targeting Germany. In this new malicious campaign, hackers are compromising WordPress websites and using SEO poisoning to display fake forum posts to visitors. These posts appear as Q&A posts that have a link that points to fake forms or downloads. When the user clicks on the link, a ZIP file containing an obscure JS file is downloaded, which installs either the Gootkit malware or the Revil ransomware. The same method was used by the REvil gang in September 2019, around the same time that Gootkit disappeared.

Gootkit malware: It returns and targets Germany together with REvil!

In a new report released yesterday, Malwarebytes researchers explain that malicious JavaScript payloads execute either Gootkit or REvil attacks. When launched, the JavaScript script connects to the C&C server and downloads another script containing the malicious malware payload.

These payloads are stored as Base64 encoded or hexadecimal strings either in a text file or split into multiple Windows. The loader ultimately reads the Registry or text file payloads, decodes them, and starts the process directly in memory. Using obfuscated payloads makes it more difficult for security software to detect malicious payloads.

Gootkit malware: It returns and targets Germany together with REvil!

It is noteworthy that security researcher “The Analyst” while investigating this malicious campaign discovered that the Revil infection left victims with ransom notes that have been used in previous attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS