Cybercriminals often exploit the tendency of many users to turn to software cracks, game cracks, and other pirated software. According to Kaspersky, some such criminals are behind a new malware dropper called “NullMixer,” which is capable of infecting Windows devices with a dozen different malware families at once. search results Google.

NullMixer acts as an infection funnel, using a single Windows executable to launch a dozen different malware families. Devices are at risk from password-stealing trojans, backdoors, spyware, bankers, fake Windows system cleaners, clipboard hijackers, cryptocurrency miners, and other malware loaders.
See also: Adware: Ad-fraud apps found in Play Store and App Store
As mentioned above, to achieve the initial infection with the NullMixer malware dropper, the malware distributors use “black hat SEO” to display sites promoting fake game cracks and pirated software in Google search results. The criminals ensure that the malicious sites appear high in Google search results.
BleepingComputer tried a Google search for “software crack” and many of the websites said to be distributing this malware were listed in the search results in second, third, and fourth place.

Unsuspecting users who attempt to download software from these malicious sites are redirected to other malicious sites that install a password-protected ZIP file containing a copy of the NullMixer malware dropper .
Because software cracks and cheats usually modify game files, users who download them ignore AV warnings about potentially dangerous executables, bypassing security checks.
See also: New info-stealer malware Erbium is distributed via game cracks
Kaspersky researchers were the first to discover this dropper. The researchers report that NullMixer has already attempted to infect 47,778 of its customers in the United States, Germany, France, Italy, India, Russia, Brazil, Turkey, and Egypt.
Infection with 12 different malware
NullMixer is usually downloaded as a file and when opened, a new file is created.
This new file is responsible for downloading dozens of malware and, once it does, launches another executable file.
This third file allows all malware to initiate their malicious activity on the compromised machine using a coded list of their names and the Windows cmd.exe tool .
See also: Hackers experiment with "data destruction" attacks
Some malware families installed on Windows systems by NullMixer include Redline Stealer, Danabot, Raccoon Stealer, Vidar Stealer, SmokeLoader, PrivateLoader, ColdStealer, Fabookie, PseudoManuscrypt, and others.
It is not common to see simultaneous infection by so many malware. The operators of NullMixer may want to make sure they inflict a lot of damage on the victim, or they may be trying to promote their tool as a very effective dropper.
However, being infected with so much malware at once will definitely leave behind many signs for the victim to realize that something is wrong (e.g., intense hard drive activity, increased CPU and memory usage, unusual windows opening for no reason, or a noticeable performance issue).
Therefore, such an infection cannot remain hidden for long.
If you want to protect yourself against the NullMixer malware dropper and other similar threats, avoid downloading pirated software and generally downloading files from unofficial online sources.
Source: www.bleepingcomputer.com
