Cybercriminals rent WikiLoader to attack Italian organizations with banking trojan.

Italian organizations are the target of a new phishing that exploits a new type of malware called WikiLoader, aiming to install a banking trojan, a stealer and spyware called Ursnif (also known as Gozi).
WikiLoader is so named because the malware makes a request to Wikipedia and checks that the response has the string “The Free”.
The enterprise security company reported that the malware was first detected on December 27, 2022, in connection with an intrusion carried out by an actor called TA544, also known as Bamboo Spider and Zeus Panda.
The campaigns focus on using emails containing either Microsoft Excel, Microsoft OneNote or PDF files that act as a lure to install the downloader, which is then used to install Ursnif.
In an indication that WikiLoader is being shared among multiple cybercriminal groups, the threat actor with the alias TA551 (also known as Shathak) has been observed using the malware since late March 2023.

Recent attacks by the TA544 threat actor, detected in July 2023, have used accounting issues to spread PDF with URLs that, when clicked, lead to the delivery of a ZIP, which in turn contains a JavaScript file designed to download and execute WikiLoader.
WikiLoader is a highly sophisticated program that maneuvers to evade detection by endpoint security software and avoid activation in automated analysis environments. In addition, it is designed to retrieve and execute a shellcode hosted on Discord, which is ultimately used to launch Ursnif.
“It is currently under active development and its authors appear to be making regular changes to try to remain undetected,” said Selena Larson, senior threat intelligence analyst at Proofpoint.
"It is likely that more criminal actors will use it, especially those known as initial access brokers (IABs) who conduct regular activity leading to ransomware. Defenders should be aware of this new malware and the activities involved in payload delivery and take steps to protect their organizations from exploitation.".
Information source: thehackernews.com
