Security researchers are warning about a relatively new malware loader, which they are tracking as Verblecon, which is sophisticated and powerful enough for ransomware attacks, although it is currently used for low-reward attacks.
See also: Ukraine shuts down 5 bot farms that spread fake news

Despite being around for over a year, samples from the Verblecon malware enjoy a low detection rate due to the polymorphic nature of the code.
Under the radar
Researchers from Symantec, a division of Broadcom Software, discovered Verblecon in January of last year and observed it being used in attacks that installed cryptocurrency miners on compromised machines.
Some indications suggest that the attacker is interested in stealing access tokens for the Discord chat app, the researchers say, adding that these goals contrast with the realistic capabilities of the Verblecon malware, which can carry out much more damaging attacks.
The malware is Java-based and its polymorphic nature is what allows it to remain undetected in many cases. The fact that the file is polymorphic means that, due to encryption and obfuscation, the malware payload code looks different each time it is downloaded.
A look at five Verblecon samples analyzed by the researchers shows that many of the antivirus engines on VirusTotal do not flag them as malicious.
The oldest sample, for example, was added to the database on October 16, 2021, and is currently detected by 9 out of 56 antivirus engines.
The newer Verblecon payloads, however, as of late January 2022, are not detected at all by antivirus engines on VirusTotal.
See also: SonicWall code update: Not available for all devices
Symantec published a technical analysis of the malware and its operations, noting that the samples analyzed may be based on publicly available code.
Their analysis shows that the malware performs certain checks to determine if it is running in a virtual environment, if it has been debugged.
It then retrieves the list of running processes that is checked in a predefined directory that includes files (executables, dependencies, drivers) related to virtual machine systems.
If all checks pass, the malware copies itself to a local directory (%ProgramData%, %LOCALAPPDATA%, Users) and creates files to use as a loading point.
According to Symantec's research, Verblecon periodically attempts to connect to one of the following domains, using a domain generation algorithm (DGA) for a more comprehensive list:
· hxxps://gaymers[.]ax/
· hxxp://[DGA_NAME][.]tk/
The DGA used is based on the current time and date and includes the string “verble” as a suffix, which is where the malware’s name comes from.
In the technical report published today, Symantec researchers note that the payload delivered after the initial stage of communication with the command and control (C2) servers “is obfuscated in a similar manner to the other samples and contains similar techniques for probing the virtualization environment.”
According to the analysis, the main function of the payload is to download and execute a binary (.BIN file) which is then decrypted on the infected host and injected into %Windows%SysWow64dllhost.exe for execution.
Researchers say the ultimate goal of whoever is behind the Verblecon deployments is to install cryptocurrency mining software, which is out of proportion to the effort required to develop malware of such complexity.
Additionally, researchers suspect that the threat actor may be using it to steal Discord tokens to use for advertising trojanized video game software. Researchers suspect that Discord tokens are also being stolen because some of the obfuscated strings refer to pathnames that are apparently related to Discord clients.
According to their observations, Verblecon targets non-business machines, which rarely fall within the scope of more sophisticated threat actors due to their low profitability.
Symantec says it is aware of other reports that have linked a Verblecon domain to a ransomware attack, but they believe this overlap is due to sharing infrastructure with an unrelated actor.

See also: SunCrypt ransomware: New version with more features
Similarities between this incident and the activity we observed include the following:
· the use of “verble” in the domain name
· downloading the shellcode for execution
· similar obfuscation
Researchers believe that Verblecon is currently being used by a hacker who does not recognize the full destructive potential of this malware loader
They believe that if more sophisticated cybercriminals get their hands on it, they could use it for ransomware and even espionage attacks.
Information source: bleepingcomputer.com
