HomeSecurityMalicious Notepad++ installers infect systems with malware

Malicious Notepad++ installers infect systems with malware

The hacking group StrongPity is behind a recent campaign exploiting Notepad++. The group has been around since 2012 and uses much the same tactics, namely adding backdoors to legitimate software used by specific users, a technique known as water holing. The group is also known as APT-C-41 and PROMETHIUM . In 2016, Kaspersky detected a StrongPity campaign targeting specific users in Belgium and Italy who were interested in Truecrypt and Winrar software. The most recent malware attacks exploit Notepad++ , a very popular, free text editor and source code for Windows, used by many organizations.

See also: Emotet installs Cobalt Strike on devices allowing for faster ransomware infection

Notepad++ malware

The modified Notepad++ installer was discovered by a threat analyst known as “blackorbird.” Minerva Labs also reports the malware.

When the malicious Notepad++ installer is executed, the file creates a folder named “Windows Data” in C:\ProgramData\Microsoft and installs the following three files:

  • npp.8.1.7.Installer.x64.exe – the original Notepad++ installation file in the C:\Users\Username\AppData\Local\Temp\ folder.
  • winpickr.exe – a malicious file in the C:\Windows\System32 folder.
  • ntuis32.exe –keylogger in C:\ProgramData\Microsoft\WindowsData folder

The installation of Notepad++ continues normally and the victim is unaware of the other two malicious files being secretly installed in the background.

As the installation completes, a new service named “PickerSrv” is created, which establishes the persistence of the malware.

This service runs 'ntuis32.exe', which is the keylogger component of the malware.

See also: Macs: Are they vulnerable to viruses/malware? Do they need antivirus?

The keylogger records all keystrokes of the victim and stores them in hidden system files created in the 'C:\ProgramData\Microsoft\WindowsData' folder. The malware also has the ability to steal files and other data from the system.

StrongPity

This folder is constantly monitored by 'winpickr.exe' and when a log file is detected, the component creates a C2 connection to send the stolen data to the attackers.

Once the data transfer is complete, the original log is deleted to eliminate traces of malicious activity.

Trust only legitimate sources

If you must use Notepad++, make sure to get an installer from the official website.

The software is available on many other websites, and many of them claim to be the official Notepad++ portals, but they may include adware or other unwanted software.

The URL that distributed the malicious Notepad++ installer has been removed after its discovery by analysts, but attackers may find another way to spread the malware.

See also: QNAP: NAS devices targeted with cryptomining malware

Follow the security measures that apply to all software tools you use, no matter how specialized they are. Cybercriminals are particularly interested in specialized software used by specific users and organizations.

In this case, the chances of detection by an AV tool would be around 50%, so it is very important to use up-to-date security tools.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS