HomeSecurityHackers abuse MSBuild and infect users with info-stealing malware

Hackers are abusing MSBuild and infecting users with info-stealing malware

Cybercriminals are abusing the Microsoft Build Engine (MSBuild) to develop remote access tools (RATs) and fileless info-stealing malware.

See also: Microsoft: Hackers target airline organizations with new malware!

MSBuild
Hackers are abusing MSBuild and infecting users with info-stealing malware

The MSBuild (msbuild.exe) is an open-source, legitimate development platform from Microsoft, for building applications.

This tool can create applications on any Windows system, if provided with an XML schema project file, which tells it how to automate the build process (compilation, packaging, testing and deployment).

As the Anomali, the malicious MSBuild project files delivered in this hacking campaign bundled coded executables and shellcode that the criminals used to inject the final payloads into the memory of recently spawned processes.

See also: Teabot: New Android malware targets banks in Europe!

“While we were unable to determine the distribution method of the .proj files, the goal of these files was to execute either Remcos or RedLine Stealer,” Anomali analysts said.

Theft of credentials and other sensitive information

Attackers began installing the Remcos RAT, Quasar RAT , and RedLine Stealer payloads on their victims' computers last month.

Hackers are abusing MSBuild and infecting users with info-stealing malware
Hackers are abusing MSBuild and infecting users with info-stealing malware

Once installed on a targeted system, info-stealing RATs can be used to record keystrokes, steal credentials, take screenshots, and can even disable antivirus software, remain on systems for a long time, and take full control of devices remotely.

Info-stealing malware scans for web browsers, messaging apps, VPNs, and cryptocurrency software to steal users' credentials.

RedLine Stealer can also collect system information, cookies, and crypto wallet information from configuration files and app data stored on victims' devices.

info-stealing malware
Hackers are abusing MSBuild and infecting users with info-stealing malware

delivery helps avoid detection

The use of Microsoft's legitimate MSBuild tool allows attackers to evade detection while loading their malicious payloads directly into the memory of a targeted computer.

See also: Cuba ransomware collaborates with Hancitor malware for spam attacks

These attacks are not detected or detected by a very small number of anti- malware.

According to a security report, the delivery of fileless malware has increased significantly since 2020.

Anomali highlighted that criminals were using fileless malware to bypass security systems.

“This campaign underscores that relying solely on antivirus software is not sufficient for cyber defense“.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS