HomeSecurityWailingCrab Malware Loader is distributed via phishing emails

The WailingCrab Malware Loader is distributed via phishing emails

Phishing emails about product delivery and shipping are being used to distribute a sophisticated malware loader, known as WailingCrab.

WailingCrab Malware

“The malware itself is divided into multiple components, including a loader, an injector, a downloader and a backdoor, and successful requests to C2-controlled servers are often necessary to retrieve the next stage,” said IBM X-Force researchers Charlotte Hammond, Ole Villadsen and Kat Metrick.

WailingCrab, also known as WikiLoader, was first documented by Proofpoint in August 2023. At the time, the malware was used to attack Italian organizations. The ultimate goal was to infect with the Ursnif (also known as Gozi) trojan.

See also: Konni malware: Distributed via phishing emails and targets Russian users

The malware appears to be the creation of the TA544, which is also tracked as Bamboo Spider and Zeus Panda. IBM X-Force named the group Hive0133.

The malware incorporates features that prioritize stealth and avoiding detection and analysis. To further reduce the chances of detection, legitimate, compromised websites are used for initial command-and-control (C2) communications.

Additionally, the malware components are stored on well-known platforms such as Discord and MQTT, a lightweight messaging protocol for small sensors and mobile devices, is used for C2.

The attack begins by sending phishing emails containing PDF. These files contain URL links. If the user clicks on them, a JavaScript file that is designed to retrieve and launch the WailingCrab loader hosted on Discord.

The loader is responsible for launching the next-stage shellcode, an injector module which, in turn, starts the execution of a downloader to ultimately deploy the backdoor.

See also: ClearFake: Malicious campaign targets Macs to distribute Atomic infostealer

The backdoor is designed to create persistence on the infected system and communicate with the C2 server using the MQTT protocol to receive additional payloads.

Additionally, newer variants of the backdoor avoid a Discord-based download path in favor of a shellcode-based payload directly from the C2 via MQTT.

“The use of the MQTT protocol by the WailingCrab malware represents a focused effort for secrecy and evasion of detection”, the researchers concluded. “The newer variants of WailingCrab also remove messages on Discord for payload retrieval, further increasing its secrecy“.

“Discord has become an increasingly common choice for threat looking to host malware, and as such it is likely that file downloads from the domain will begin to be subject to higher levels of scrutiny. So it is no surprise that the developers of WailingCrab decided on an alternative approach.“.

phishing

One of the key ways to prevent a attack is to use up-to-date software. Malicious users often exploit vulnerabilities in old software versions to infiltrate systems. Therefore, it is important to check and update your software on a regular basis.

See also: War in Gaza: Phishing campaign deceives victims with alleged donations

Another important preventive measure is to be careful when opening emails and attachments. Avoid opening messages from unknown senders or with suspicious content. Also, do not click on attachments that you were not expecting or that look suspicious.

Additionally, using strong passwords is crucial to protect against WailingCrab malware. Choose long and complex passwords that include letters, numbers, and special characters. Avoid reusing your passwords across different services.

Finally, installing and updating reliable security software is essential for protection against malware. A good security program can detect and isolate malware before it can cause damage to your system.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS