HomeSecurityBunnyLoader: A new Malware-as-a-Service threat has emerged

BunnyLoader: A new Malware-as-a-Service threat has emerged

Cybersecurity experts have discovered yet another Malware-as-a-Service threat, called BunnyLoader, advertised for sale on various cybercrime forums on the dark web.

BunnyLoader

“BunnyLoader provides various functionalities, such as downloading and executing a second-stage payload, stealing browser credentials and system information, and more,” Zscaler ThreatLabz researchers Niraj Shivtarkar and Satyam Singh said in an analysis published last week.

Its other capabilities include executing remote commands on the infected machine, a keylogger to record keystrokes, and a clipper function to monitor the victim's clipboard and replace content matching cryptocurrency wallet with addresses controlled by the attacker.

A C/C++-based loader offered for $250 for a lifetime license, the malware is said to be under continuous development since its first appearance on September 4, 2023, with new features and improvements incorporating anti-sandboxing techniques and antivirus protection.

Also fixed as part of the updates released on September 15 and September 27, 2023, were issues with commands and control (C2) as well as “critical” SQL injection flaws in the C2 table that would have granted access to the database.

A key selling point of BunnyLoader, according to author PLAYER_BUNNY (aka PLAYER_BL), is its fileless loading feature which “makes it difficult for antivirus programs to remove the malware.”.

The C2 panel provides buyers with options to monitor active tasks, infection statistics, total number of connected and inactive nodes, and stealer logs. It also provides the ability to purge information and remotely control compromised machines.

The exact initial access method used to distribute BunnyLoader is still unclear. Once installed, the malware establishes a persistent presence by altering the Windows Registry and performs a series of sandbox and virtual machine before activating its malicious behavior by sending work requests to the remote server and receiving the desired responses.

This includes Trojan Downloader tasks to download and execute malware at a later stage, Intruder to execute keyloggers and stealers to collect data from messaging apps, VPN clients, and web browsers, and Clipper to redirect cryptocurrency payments.

The final step involves encapsulating all collected data into a ZIP file and transmitting it to the server.

BunnyLoader: A new Malware-as-a-Service threat has emerged

“BunnyLoader is a new MaaS threat that is constantly evolving its tactics and adding new features to carry out successful campaigns against its targets,” the researchers said.

Cybercriminals are not only offering new malware services, but also enhancing the features of existing MaaS platforms with updated attack chains to evade detection by security tools. This includes a variant of RedLine Stealer that uses a Windows Batch script to execute the malware.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS