HomeSecurityMalware has infiltrated the Microsoft Store using game clones

Malware has infiltrated the Microsoft Store using game clones

A malware called Electron Bot managed to infiltrate the Microsoft Store by creating clones of popular games like Subway Surfer and Temple Run. The result was to infect around 5,000 computers in Sweden, Israel, Spain and Bermuda.

The malware was discovered and analyzed by Check Point researchers and is actually a backdoor that gives attackers complete control over compromised machines. It allows remote command execution and real-time interactions.

See also: MuddyWatter: Iranian hackers use new malware and target critical infrastructure

Microsoft Store malware

Electron Bot enables attackers to take control of social media accounts (e.g. Facebook, Google, YouTube and Sound Cloud), as the malware supports new account registration, comments and likes on these platforms.

Three years of development

The hacking campaign was first discovered in late 2018, when an early Electron Bot variant was passed on to the Microsoft Store as “Album by Google Photos,” published by a spoofed entity, Google LLC.

Since then, the malware's creators have added many new features and evasion capabilities.

Malware can mimic normal browsing behavior and perform actions as if it were a real website visitor.

See also: Ransomware attacks: The nightmare doesn't stop after the ransom is paid

To do this, it opens a new hidden browser window using the Chromium engine in the Electron framework, sets the appropriate HTTP headers, renders the requested HTML page, and finally performs mouse movement, scrolling, clicking, and typing.

According to Check Point researchers, Electron Bot's primary targets in this new campaign are:

  • SEO poisoning – Creating malicious sites that rank high in Google search results.
  • Ad Clicking – Connecting to remote sites in the background and clicking on ads for financial gain.
  • Social media account promotion – Directing traffic to specific content on social media platforms.
  • Online product promotion

The above are offered as services to those who want to illegally increase their online profits, so the profits for the operators of Electron Bot are indirect.

Check Point researchers say the attacks are likely related to hackers from Bulgaria, but nothing else is known about their identities.

Electron Bot
Malware has infiltrated the Microsoft Store using game clones

How does infection occur?

The Electron Bot infection chain begins with the victim installing one of the cloned apps from the Microsoft Store. Upon opening the app, a JavaScript dropper is loaded in the background to retrieve the Electron Bot payload and install it.

The malware starts running at the next system startup, connects to the C2 (Electron Bot[.]s3[.]eu-central-1[.]amazonaws.com or 11k[.]online), retrieves its configuration, and executes commands.

According to the researchers, all games operate normally, while malicious operations unfold in the background.

This results in positive user reviews on the Microsoft Store. For example, Temple Endless Runner 2, which was released on September 6, 2021, has a near-perfect five-star rating from 92 people.

See also: Asia in 2021 received one in four cyberattacks carried out globally

Of course, scammers are constantly using different game titles and apps to deliver malicious payloads to unsuspecting victims.

Malware has infiltrated the Microsoft Store using game clones

As can be seen from the above, the existing version of Electron Bot does not cause catastrophic damage to infected Windows machines, but threat actors can easily modify the code to install a second-stage payload, such as a RAT or even ransomware.

Check Point recommends that Windows be cautious when downloading applications even from official sources, such as the Microsoft Store. They should avoid downloading applications with low reviews, carefully check the developer/publisher details, and ensure that the application name is spelled correctly.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS