HomeSecurityBundleBot malware steals sensitive information

BundleBot malware steals sensitive information

A new malware strain called BundleBot operates by exploiting .NET file deployment techniques, allowing threat actors to steal sensitive information from infected computers.

See also: Roblox: Previous data breach exposed 4000 users' details

BundleBot malware steals sensitive information

Some of these websites aim to imitate Google Assistant, the company's artificial intelligence robot, by tricking victims into downloading a fake RAR file (“Google_AI.rar”) hosted on legitimate cloud storage services, such as Dropbox.

The archive file, when unzipped, contains an executable file (“GoogleAI.exe”), which is a single-file, self-contained .NET application, which, in turn, embeds a DLL file (“GoogleAI.dll”) responsible for retrieving a password-protected ZIP file from Google Drive.

See also: Two critical AMI MegaRAC vulnerabilities identified

The contents of the extracted ZIP file (“ADSNEW-1.0.0.3.zip”) are another single-file, self-contained .NET application (“RiotClientServices.exe”) that embeds the BundleBot payload (“RiotClientServices.dll”) and a command and control (C2) packet data serializer (“LibrarySharing.dll”).

The binary artifacts use specially crafted obfuscation and junk code in an attempt to resist analysis and have the capabilities to extract data from web browsers, take screenshots, steal Discord tokens, Telegram information , and Facebook account details .

Check Point reported that it has also detected a second BundleBot sample that is almost identical in all aspects, except for the use of HTTPS to leak information to a remote server in the form of a ZIP file.

This development comes as Malwarebytes uncovered a new campaign that uses sponsored posts and has compromised verified accounts, which impersonate Facebook Ads Manager to trick users into downloading rogue Google Chrome extensions designed to steal Facebook login information

Users who click on the embedded link are prompted to download a RAR archive file containing an MSI installation file which, in turn, launches a batch script to create a new Google Chrome window with the malicious extension loaded using the “–load-extension” flag.

BundleBot malware steals sensitive information

The captured data is then sent through the Google Analytics API to bypass content security policies (CSPs) to mitigate Cross-Site Scripting (XSS) and data injection attacks.

See also: Mallox ransomware exploits weak MS-SQL servers to compromise networks

The threat actors behind the activity are believed to be of Vietnamese origin and have shown a keen interest in targeting business and advertising accounts on Facebook in recent months. Over 800 victims worldwide, including 310 in the US, have been affected.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS