HomeSecurityNimzaLoader malware is written in Nim to evade detection

NimzaLoader malware is written in Nim to evade detection

Cybercriminals are distributing a new malware, but it has a unique feature. It is written in a programming language that is rarely used for malicious code. Proofpoint researchers have named this malware NimzaLoader .

NimzaLoader malware

The NimzaLoader malware is written in the Nim. Researchers believe that the hackers behind the malware designed it this way, hoping that choosing an unusual programming language would make it more difficult to detect and analyze.

See also: Go malware has increased by 2000% in recent years

NimzaLoader malware provides access to Windows computers and gives attackers the ability to execute commands. This means that criminals can control the machine, steal sensitive information, or deploy additional malware.

See also: Windows Defender: 12-year-old bug gives hackers administrator privileges

Researchers believe the malware is the work of a group that Proofpoint has dubbed TA800. This group has targeted organizations across multiple industries in North Africa.

The group has also been linked to BazarLoader, a trojan that creates a backdoor on compromised Windows computers and is commonly used to carry out ransomware attacks.

Like BazarLoader, NimzaLoader is distributed via phishing emails that link victims to a fake PDF downloader, which, if executed, will download the malware onto the machine. Phishing emails are usually elaborate and include victims' personal information to make them appear more convincing.

The message template and payload delivery method are consistent with previous TA800 phishing campaigns. For this reason, researchers believe that the NimzaLoader malware likely belongs to this group.

Nim programming language

“TA800 has leveraged different and unique malware, and the developers may have chosen to use an unusual programming language, such as Nim, to avoid detection, as reverse engineers may not be familiar with the Nim implementation, and therefore tools and sandboxes may have difficulty analyzing this sample,” said Sherrod DeGrippo, senior director of threat research and detection at Proofpoint.

As phishing is the primary distribution method of NimzaLoader, organizations should protect their network with tools that prevent malicious emails from arriving in the Inbox.

Useful information:Phishing emails: How to recognize them and how to protect yourself?

Organizations should also train employees to recognize phishing emails.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS