HomeSecurityHackers use icon files to distribute NanoCore Trojan

Hackers use icon files to distribute NanoCore Trojan

A new malspam (phishing) campaign uses icon files to trick victims into running the NanoCore Trojan on their device without them knowing.

 NanoCore Trojan phishing

On Thursday, SpiderLabs , Trustwave 's ethical hacking team , said it had observed a new phishing campaign that uses a technique to spread NanoCore, a remote access Trojan (RAT).

See also: Malicious Google Play apps place Trojans on devices

The phishing emails that victims receive are supposedly from a “Purchase Manager” of organizations, which are usually business partners, etc.

See also: Microsoft email: Users receive phishing emails that impersonate couriers

Of course, hackers make sure to use the logos of the organizations etc. to make it look like the email really comes from there. Phishing emails contain an attachment, named “NEW PURCHASE ORDER.pdf * .zipx“. In reality they are image binary files.

The icons have additional information in .RAR format.

By using icon files, scammers are likely trying to evade email security filtersimplemented by organizations.

icon files

If the victim clicks on the attachment and their computer has an unzip tool, such as WinZip or WinRAR, an executable file is extracted. 7Zip can also extract the file, but it takes more than one attempt.

Successful extraction leads to the development of NanoCore Trojan version 1.2.2.0. The Trojan was first detected in 2013 and includes various capabilities, such as keylogging, information theft, and installing a dropper for additional malware. It can also access and steal video from a camera, as well as extract data and send it to a command-and-control (C2) server.

Researchers have seen the NanoCore Trojan being sold on underground forums.

Most often, it is distributed through phishing campaigns, related to financial matters.

Useful information: Phishing attacks: What are they and how do hackers usually attack?

This version of the Trojan can create copies of itself in the AppData folder and affect the RegSvcs.exe process. The information stolen by the malware is sent to multiple C2s.

The technique of using icon files to distribute the NanoCore Trojan is similar to a previous phishing campaign that also used .zipx. In 2019, researchers reported that another Trojan, named Lokibot, was spread through malspam campaigns with attachments with .zipx extensions and .JPG icons.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS