A new APT hacking group called AtlasCross is targeting organizations with phishing lures impersonating the American Red Cross to deliver backdoor malware.
Cybersecurity firm NSFocus has identified two undocumented trojans, DangerAds and AtlasAgent, that are associated with attacks by the new APT group.
NSFocus reports that the AtlasCross hackers are sophisticated, preventing researchers from determining their origins.

The AtlassCross group's attacks begin with a phishing email pretending to be from the American Red Cross, asking the recipient to participate in a “September 2023 Blood Drive.”
These emails contain a macro-enabled Word document (.docm) attachment that prompts the victim to click “Enable Content” to view the hidden content.
However, doing so will trigger malicious macros that infect your Windows device with the DangerAds and AtlasAgent malware.

The macros first extract a ZIP file to the Windows device to drop a file named KB4495667.pkg, which is the DangerAds system profiler and malware loader. A scheduled task named “Microsoft Office Updates” is created to launch DangerAds daily for three days.
DangerAds acts as a loader, evaluating the host environment and executing embedded shellcode if specific strings are found in the system's username or domain name, an example of AtlasCross' narrow targeting scope.
Finally, DangerAds loads x64.dll, which is the AtlasAgent trojan, the final payload delivered in the attack.

AtlasAgent Details
AtlasAgent is a custom C++ trojan and its main functions include extracting host and process details, preventing multiple programs from starting, executing additional shellcode on the compromised machine, and downloading files from the attacker's C2 servers.
Upon first launch, the malware sends information to the attacker's servers, including the local computer name, network adapter information, local IP address, network card information, operating system architecture and version, and a list of running processes.
The attacker's servers will then respond with commands to execute AtlasAgent, which can be done using new threads or within one of the existing processes, making it harder for security tools to detect and stop.
While NSFocus' report is the first to detail the new hacking group, AtlasCross remains a largely unknown threat that operates with unclear motives and a murky targeting scope.
The group's selective targeting, specially crafted trojans, and malware loaders, combined with a preference for discreet infection methods over efficiency, allowed them to operate undetected for an indefinite duration.
Information source: bleepingcomputer.com
