Since the summer of 2022, hackers have launched a malicious malvertising attack with OpcJacker – a sneaky malware that steals personal information.

Our initial campaign strategy involved a web of fake websites advertising fake cryptocurrency-related software and apps. The February 2023 campaign specifically targeted users in Iran under the guise of offering a VPN service.
See also: Pinduoduo: Chinese app spies on users and competitors
OpcJacker's installation files act as a delivery method for the malicious tool. It is also capable of delivering further payloads such as the NetSupport RAT and a disguised version of virtual network computing (hVNC) to provide attackers with remote access.
OpcJacker is hidden through the use of a cryptographer known as Babadeda and relies on a configuration file to initiate its data-stealing capabilities. It also has the ability to launch arbitrary shellcode and executable files.

See also: Hackers exploit bug in Elementor Pro WordPress plugin
Undoubtedly, this malware is financially motivated due to its ability to steal crypto funds from wallets. However, OpcJacker's reusability also makes it a prime candidate as a malware loader.
According to Securonix, an ongoing cyberattack campaign dubbed TACTICAL#OCTOPUS is underway in the United States. Using malicious tax-, this attack aims to implant backdoors that can give criminals access to systems they have access, as well as obtain confidential data, such as clipboard contents and keystrokes.
In a related development, Italian and French users searching for cracked versions of computer maintenance software, such as EaseUS Partition Master and Driver Easy Pro on YouTube, are being redirected to Blogger pages distributing the NullMixer dropper.
See also: Western Digital: Announces network breach
NullMixer has been identified as the perpetrator of large-scale malware infections due to the development of various ready-made viruses, such as PseudoManuscrypt, Raccoon Stealer, GCleaner, Fabookie, and Crashtech Loader.
Information source: thehackernews.com
