HomeSecurity100,000 Google sites used to install SolarMarket RAT

100,000 Google sites used to install SolarMarket RAT

Hackers are using search engine optimization (SEO) to lure business users to over 100,000 malicious Google sites that appear legitimate, but actually install a remote access trojan (RAT) – SolarMarket – that is used to compromise a network and then “infect” systems with ransomware, credential-stealers, banking trojans and other malware.

eSentire 's Threat Response Unit (TRU) discovered malicious sites containing popular business terms/specific keywords, including business-form keywords such as template, invoice, receipt, questionnaire, and resume , researchers said in a report published on April 14.

Read also: QBot trojan replaces IcedID in malspam campaigns!

100,000 Google sites used to install SolarMarket RAT
100,000 Google sites used to install SolarMarket RAT

Attackers use Google search redirection and drive-by-download tactics to direct unsuspecting victims to the RAT — which eSentire has dubbed “SolarMarket” (other names it has been called include Jupyter, Yellow Cockatoo, and Polazert). Typically, a person visiting the “infected” site simply executes a binary that is in PDF format by clicking on a supposed “form” — thus infecting their device.

Additionally, the researchers noted the following: "This is an increasingly common trend in malware distribution. Unfortunately, this reveals a significant blind spot in the controls, which allows users to execute untrusted binaries or script files."

See also: Hackers distribute malware using contact forms with Google URLs

This is a malicious campaign that is not only extensive but also sophisticated.

100,000 Google sites used to install SolarMarket RAT
100,000 Google sites used to install SolarMarket RAT

The most common business terms serve as keywords for the threat actors’ search optimization strategy, convincing Google’s web crawler that the content qualifies for a high page rank, meaning the malicious sites will appear at the top of users’ searches, according to the report. This increases the likelihood that victims will be enticed to visit infected sites.

Suggestion: How can you block sites in Google Chrome?

Spence Hutchinson, director of threat intelligence at eSentire, said: “Security leaders and their teams should be aware that the hackers behind SolarMarket have gone to great lengths to target business professionals, casting a wide net, and employing multiple tactics to successfully cover their traps.”

The researchers describe a recent incident they discovered in which a victim working in the financial industry was searching for a free version of a document online and was redirected via Google Search to a Google sites page that was under the control of the hackers and included a built-in download button.
As the researchers say, someone working in the financial industry would be a “high-value target” of the campaign, giving attackers several methods to compromise an organization and commit cybercrime.

100,000 Google sites used to install SolarMarket RAT
100,000 Google sites used to install SolarMarket RAT

Additionally, the researchers noted: “Once a RAT is installed on a victim’s computer, hackers can distribute additional malware to the device, such as a banking trojan, which could be used to compromise an organization’s online banking credentials. Hackers could also install a credential-stealer this way to collect an employee’s email credentials and launch a BEC (Business Email Compromise) attack. Unfortunately, once a RAT is installed, the potential for fraud activities is numerous.”

According to TRU, the RAT is written in the Microsoft .NET framework and has used various decoy applications that are downloaded to a victim's computer and appear to belong there. Most recently, TRU observed that Slim PDF reader software was the decoy downloaded. This serves as a distraction, as well as an additional element to convince the victim that they are downloading a PDF.

In the last few months of 2020, hackers used other file types for decoy apps, including docx2rtf.exe, photodesigner7_x86-64.exe, Expert_PDF.ex, and docx2rtf.exe, according to the report.

Source of information: threatpost.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS