HomeSecurityHackers use fake Onlyfans content to infect users with DcRAT...

Hackers use fake Onlyfans content to infect users with DcRAT malware

A new malicious campaign is using fake OnlyFans content and adult lures to install a remote access known as “DcRAT” on victims’ devices. The DcRAT trojan will allow attackers to steal data and credentials or execute ransomware on the infected device.

Onlyfans

OnlyFans is a popular subscription content service where subscribers pay to access photos, videos , and posts from adult models, celebrities, and social media personalities.

Its popularity has increased recently, which is why cybercriminals are exploiting it to lure users. Victims believe they will gain free access to OnlyFans content that you normally have to pay for.

See also: ASUS: Critical vulnerabilities in routers – Update them immediately!

This is not the first time that threat actors have exploited OnlyFans. In January 2023, cybercriminals managed to direct users to fake OnlyFans websites.

The new campaign was discovered by eSentire and has also been active since January 2023. Malicious actors send files ZIP containing a VBScript loader. The program tricks victims into running it, making them believe they will gain access to premium OnlyFans collections.

We don't know many details about the infection chain, but it could start with malicious forum posts, instant messages, malicious ads , or even Black SEO sites that rank high for certain search terms. One sample shared by Eclypsium pretends to be nude photos of former adult film actress Mia Khalifa.

The VBScript loader is a minimally modified and obfuscated version of a script that was observed in a 2021 campaign. It was a slightly modified Windows printing script.

At startup, it checks the operating system architecture using WMI and creates a 32-bit process, extracts an embedded file (“dynwrapx.dll”) and registers the DLL with the Regsvr32.exe command.

See also: Compromised S3 buckets used in attacks on npm packages

DcRAT
Hackers use fake Onlyfans content to infect users with DcRAT malware

This gives the malware access to DynamicWrapperX, a tool that allows calling functions from the Windows API or other DLL files.

Eventually, the payload, called “BinaryData“, is loaded into memory and “injected” into the ‘RegAsm.exe‘ process, a legitimate part of the .NET Framework that is less likely to be flagged by tools .

The payload introduced is the DcRAT trojan mentioned above. It is a modified version of AsyncRAT that is freely available on GitHub.

DcRAT performs keylogging, webcam monitoring, file manipulation, and remote access. In addition, it can steal credentials and cookies from web browsers or grab Discord tokens.

Finally, DcRAT also has a ransomware that targets all non-system files and appends the “.DcRat” extension to encrypted files.

The above malware campaign exploiting Onlyfans shows that it is important to be cautious when downloading files or executables from dubious sources, especially those that offer free access to premium/paid content.

See also: Realme: Is it stealing user data? India launches investigation

Malware is a serious threat to your device's security, but by following a few simple steps, you can protect yourself from infection. Installing antivirus software, keeping your operating system and software up to date , using a firewall, being careful online , and backing up your data are all effective ways to protect your computer from malware.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS