HomeSecurityAmadey malware: Distributed via SmokeLoader using cracks

Amadey malware: Distributed via SmokeLoader using cracks

A new version of the Amadey Bot malware is being distributed via SmokeLoader, using software cracks and keygen websites as a lure.

Amadey Bot is a type of malware discovered four years ago, capable of performing system reconnaissance, stealing information, and loading additional payloads.

While its distribution has waned since 2020, Korean researchers at AhnLab report that a new version has been released and is supported by the equally old but still very active SmokeLoader malware .

Amadey malware: Distributed via SmokeLoader using cracks
Amadey malware: Distributed via SmokeLoader using cracks

See also: Apple and Meta shared data with hackers pretending to be researchers

This is a departure from Amadey's reliance on Fallout and Rig exploit kits, which generally have less popularity as they target older vulnerabilities.

SmokeLoader is downloaded and executed voluntarily by victims, disguised as a software crack or keygen. As it is common for cracks and keygens to trigger antivirus warnings, it is common for users to disable antivirus programs before executing the programs, making them an ideal method of distributing malware.

When executed, it injects the "Main Bot" into the current process (explorer.exe), so that the operating system trusts it and downloads Amadey to the system.

Once Amadey is retrieved and executed, it copies itself to a TEMP folder named "bguuwe.exe" and creates a scheduled task to maintain persistence using a cmd.exe.

Amadey malware: Distributed via SmokeLoader using cracks
Amadey malware: Distributed via SmokeLoader using cracks

Amadey then establishes C2 communication and sends a system profile to the threat agent's server, including the operating system version, architecture type, list of installed antivirus , etc.

In its latest version, numbered 3.21, Amadey can detect 14 antivirus products and, possibly based on the results, recover payloads that can evade the antiviruses in use.

See also: QBot attacks abuse Windows Calculator

The server responds with instructions on downloading additional plugins in the form of DLLs, as well as copies of additional information-stealing programs, mainly RedLine (yuri.exe).

The payloads are downloaded and installed by bypassing UAC and privilege escalation. Amadey uses a program named “FXSUNATD.exe” for this purpose and elevates to administrator privileges via DLL hijacking.

Also, appropriate exceptions to Windows Defender are added using PowerShell before downloading the payloads.

Amadey malware: Distributed via SmokeLoader using cracks
Amadey malware: Distributed via SmokeLoader using cracks

Additionally, Amadey captures screenshots periodically and stores them in the TEMP path for sending to the C2 with the next POST request.

One of the downloaded DLL plugins, "cred.dll", which is executed via "rundll32.exe", attempts to steal information from the following software:

  • Mikrotik Router Management Program Winbox
  • Outlook
  • FileZilla
  • Pidgin
  • Total Commander FTP Client
  • RealVNC, TightVNC, TigerVNC
  • WinSCP

Of course, if RedLine is loaded onto the host computer, the targeting range expands dramatically and the victim risks losing account credentials, communications, files, and crypto assets.

To stay away from the risk of Amadey Bot and RedLine, avoid downloading cracked files, software product activators, or illegal keygens that promise free access to premium products.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS