HomeSecurityHorabot botnet: New malicious campaign targets email accounts

Horabot botnet: New malicious campaign targets email accounts

A campaign distributing the Horabot botnet malware has been appearing in Latin America since November 2020, targeting Spanish-speaking users. The campaign infects users with a banking trojan and a spam tool.

Horabot botnet malware

The malware allows its operators to take control of the victim's Gmail, Outlook, Hotmail or Yahoo email accounts. This means that attackers can steal data and 2FA codes that arrive in the inbox, as well as send phishing emails from the compromised accounts.

The new Horabot malware operation was discovered by Cisco Talos. It is believed that the attackers are likely based in Brazil.

Phishing emails

The attack begins with a phishing email, with a tax-related subject line, and includes an HTML attachment that is supposed to be a payment receipt.

See also: SeroXen RAT malware targets gamers

If the user opens the HTML, it starts a URL redirect chain that takes the victim to an HTML page hosted on an AWS instance controlled by the attackers.

The victim clicks on the hyperlink on the page and downloads a RAR archive containing a batch file with a CMD extension. This in turn downloads a PowerShell script that retrieves trojan DLLs and some legitimate executables from the C2 server.

The trojans will essentially deliver the last two payloads from a different C2 server. One is a PowerShell downloader script and the other is the Horabot binary.

Banking Trojan

One of the DLL files in the downloaded ZIP, “jli.dll”, which is loaded by the executable “kinit.exe”, is a banking trojan. It targets system information (language, disk size, antivirus software, hostname, operating system, IP address), user credentials and activity data. In addition, it offers operators remote access and can also perform keylogging, screenshot taking and mouse event tracking.

When the victim opens an application, the trojan displays a fake window on top of it to trick the victim into entering sensitive data such as bank account credentials or one-time passwords.

All information collected from the victim's computer is sent to the attackers.

Horabot botnet: New malicious campaign targets email accounts
Horabot botnet: New malicious campaign targets email accounts

Cisco explains that the trojan has several built-in anti-analysis mechanisms to prevent it from executing in sandboxes.

See also: Ransomware groups adopt business practices to increase their profits

The ZIP file also contains an encrypted spam tool DLL named “_upyqta2_J.mdat”, which is designed to steal credentials for popular webmail services such as Gmail, Hotmail, and Yahoo.

Once the credentials are compromised, the tool takes over the victim's email account, creates spam emails and sends them to the victim, continuing the attacks on other people.

This tool also has keylogging, screenshot capture, and mouse event tracking capabilities, just like the banking trojan we mentioned above.

Horabot botnet malware

As we said at the beginning, the main payload that reaches the victim's system is Horabot, a PowerShell-based botnet malware that targets Outlook mailboxes to steal contacts and send phishing emails containing malicious HTML attachments.

The malware launches the victim's desktop Outlook application to check the address book and contacts from the mailbox contents.

“ After initialization, the [Horabot] script searches for Outlook data files from the Outlook data folder ,” Cisco explains in the report.

“It enumerates all folders and emails in data and extracts email addresses from the sender, recipient, CC and BCC fields of the emails.” All email addresses are written to a “.Outlook” file and then encrypted and sent to the C2 server.

Finally, the malware creates an HTML file locally, fills it with content copied from an external resource, and sends phishing emails to all stolen email addresses individually.

When the phishing email sending process is complete, the files and folders created locally are deleted so that there are no traces of the malware.

See also: RomCom backdoor: Distributed via fake Google Ads promoting ChatGPT and others

Currently, this Horabot campaign is primarily targeting users in Mexico, Uruguay, Brazil, Venezuela, Argentina, Guatemala, and Panama. However, successful attacks could lead the attackers to target other markets at any time.

Phishing attacks can be devastating for both individuals and businesses, as they can lead to the theft of important data and further infection with malware. By becoming familiar with different types of attacks, verifying sender information, implementing anti-phishing tools, training on new threats, and keeping systems and software updated, you can protect yourself from these types of attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS