HomeSecurityWinter Vivern hackers use fake antivirus scanners to distribute malware

Winter Vivern hackers use fake antivirus scanners to distribute malware

A hacking group, known as “Winter Vivern”, has targeted European government agencies and telecommunications providers and infected them with malware, with the aim of committing espionage.

Winter Wyvern hackers

It is believed that this group is a pro-Russian APT group, as its activities appear to correspond to the strategic interests of Russia and Belarus.

Sentinel Labs says the threat team operates with few resources, but ingenuity makes up for these limitations.

Latest developments

The Winter Vivern group was first examined by DomainTools in 2021, when it was seen targeting government organizations in the Vatican, Lithuania, Slovakia, and India.

See also: Android malware “FakeCalls” targets financial companies in South Korea

Sentinel Labs has now identified a new wave of cyberattacks targeting in government personnel Poland, Italy, Ukraine, and India. As we mentioned above, hackers have not only targeted government targets, but also companies providing services in Ukraine, especially after the Russian invasion.

In early 2023, cybercriminals created fake websites that were identical to those belonging to the Polish Central Bureau for Combating Cybercrime, the Ukrainian Ministry of Foreign Affairs, and the Security of Ukraine. These pages distribute malicious files to visitors who end up there by clicking on links in malicious emails received from the hackers.

Sentinel Labs had previously seen XLS files with malicious macros that launch PowerShell present on cloned pages.

malware

Fake virus scanners

According to a report by Sentinel Labs (via BleepingComputer), Winter Vivern is known for its resourcefulness. The group uses Windows batch files to impersonate antivirus scanners while, in reality, downloading malicious payloads.

See also: LockBit ransomware says it hacked Essendant

The malicious files supposedly perform a virus scan and display “a percentage of time remaining to complete the scan.” They secretly download a malicious payload using PowerShell.

The payload delivered through this process is called “Aperetif”. The malware is hosted on compromised WordPress websites, which are commonly used for malware distribution campaigns. Aperetif has the ability to automatically scan and extract files, take screenshots and send all data (in encrypted form) to a hardcoded command and control server URL (marakanas[.]com).

Sentinel Labs researchers recently identified a new payload used by Winter Vivern, which is similar to Aperefit in terms of function, but appears to be still in development.

In both cases, the malware beacons connect to the C2 using PowerShell and wait for instructions or additional payloads.

From the above, it appears that the hackers who make up the Winter Vivern group use a relatively simplistic but effective approach to trick users into downloading malicious files and infecting their devices.

See also: Adobe ColdFusion zero-day: Update immediately

Malware

Malware can cause serious damage, which is why it is important for all computer users and businesses/organizations to understand how different types of malware work and what steps they should take to protect devices from infection. By keeping your anti-virus/anti-malware software up to date, avoiding clicking on suspicious links in messages , avoiding installing software from unknown sources, etc., you will significantly reduce the risk of infection by various types of malware that are circulating today!

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS