HomeSecurityMagnat Campaign: Malware Spreads Through Fake Software Downloads

Magnat Campaign: Malware Spreads Through Fake Software Downloads

Hackers are using online ads for fake versions of popular software to trick users into downloading three forms of malware – including a malicious browser extension with the same capabilities as a malware trojan – that provide attackers with usernames and passwords, as well as backdoor remote access to infected Windows PCs.

Magnat malware software

The attacks, which distribute two forms of seemingly undocumented custom-developed malware, were detailed by cybersecurity researchers at Cisco Talos, who dubbed the campaign “magnat.” The campaign appears to have been operating since 2018, and the malware is in constant development.

More than half of the victims are in Canada, but there have also been victims around the world, including the United States, Europe, Australia and Nigeria.

See also: A simple technique enhances phishing campaigns to spread malware

Researchers believe that victims are tricked into downloading the malware through malvertising – malicious online advertisements – which trick them into downloading fake installers of popular software onto their systems. Users are likely looking for legitimate versions of the software, but are directed to the malicious versions through advertising.

What does this software that deceives users include? Fake versions of messaging apps like Viber and WeChat, as well as fake installers for popular video games like Battlefield.

Magnat malware software

The installer does not install the advertised software, but instead installs three forms of malware – a password stealer program, a backdoor, and a malicious browser extension, which allows keylogging and taking screenshots of what the infected user is viewing.

The password stealer distributed in the attacks is known as Redline, a relatively common malware that steals all usernames and passwords it finds on the infected system. The Magnat campaign previously distributed a different password stealer, Azorult. The switch to Redline likely happened because Azorult, like many other forms of malware, stopped working properly after the release of Chrome 80 in February 2020.

See also: eCommerce servers targeted with malware hiding in Nginx servers

While password stealers are both off-the-shelf malware, the undocumented backdoor installer – which researchers have dubbed MagnatBackdoor – appears to be a more customized form of malware that has been distributed since 2019, although there are times when distribution has been halted for months.

MagnatBackdoor configures the infected Windows system to allow Remote Desktop Protocol (RDP) access. It adds a new user and schedules the system to ping a command and control server run by the attackers at regular intervals. The backdoor allows attackers to secretly gain remote access to the computer when needed.

The third payload is a downloader for a malicious Google Chrome extension, which the researchers named MagnatExtension. The extension is provided by the attackers and does not come from the Chrome Extension Store.

Magnate

This extension contains various means of stealing data directly from the web browser, including the ability to download payloads, steal cookies, steal information entered into forms, and a keylogger, which records everything the user types in the browser. All of this information is then sent to the attackers.

See also: Finland: Flubot banking malware infects Android devices

Researchers have likened the extension's capabilities to a banking trojan. They say the malware's ultimate goal is to acquire user credentials, either for sale on the dark web or for further exploitation by attackers. The cybercriminals behind MagnatBackdoor and MagnatExtension have spent years developing and updating the malware, and this is likely to continue.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS