HomeSecurityAtlasCross Group: Using the American Red Cross as a phishing lure

AtlasCross Group: Using the American Red Cross as a phishing lure

A new APT hacking group called AtlasCross is targeting organizations with phishing lures impersonating the American Red Cross to deliver backdoor malware.

Cybersecurity firm NSFocus has identified two undocumented trojans, DangerAds and AtlasAgent, that are associated with attacks by the new APT group.

NSFocus reports that the AtlasCross hackers are sophisticated, preventing researchers from determining their origins.

AtlasCross

The AtlassCross group's attacks begin with a phishing email pretending to be from the American Red Cross, asking the recipient to participate in a “September 2023 Blood Drive.”

These emails contain a macro-enabled Word document (.docm) attachment that prompts the victim to click “Enable Content” to view the hidden content.

However, doing so will trigger malicious macros that infect your Windows device with the DangerAds and AtlasAgent malware.

AtlasCross Group: Using the American Red Cross as a phishing lure


The macros first extract a ZIP file to the Windows device to drop a file named KB4495667.pkg, which is the DangerAds system profiler and malware loader. A scheduled task named “Microsoft Office Updates” is created to launch DangerAds daily for three days.

DangerAds acts as a loader, evaluating the host environment and executing embedded shellcode if specific strings are found in the system's username or domain name, an example of AtlasCross' narrow targeting scope.

Finally, DangerAds loads x64.dll, which is the AtlasAgent trojan, the final payload delivered in the attack.

AtlasCross Group: Using the American Red Cross as a phishing lure

AtlasAgent Details

AtlasAgent is a custom C++ trojan and its main functions include extracting host and process details, preventing multiple programs from starting, executing additional shellcode on the compromised machine, and downloading files from the attacker's C2 servers.

Upon first launch, the malware sends information to the attacker's servers, including the local computer name, network adapter information, local IP address, network card information, operating system architecture and version, and a list of running processes.

The attacker's servers will then respond with commands to execute AtlasAgent, which can be done using new threads or within one of the existing processes, making it harder for security tools to detect and stop.

While NSFocus' report is the first to detail the new hacking group, AtlasCross remains a largely unknown threat that operates with unclear motives and a murky targeting scope.

The group's selective targeting, specially crafted trojans, and malware loaders, combined with a preference for discreet infection methods over efficiency, allowed them to operate undetected for an indefinite duration.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS