HomeSecurityZLoader: New variant of malware compatible with 64-bit Windows

ZLoader: New variant of malware compatible with 64-bit Windows

Threat researchers have identified a new campaign distributing the ZLoader, which has resurfaced nearly two years after the botnet in April 2022.

See also: RIG Exploit Kit continues to infect corporate users via Internet Explorer

ZLoader

According to an analysis published by Zscaler ThreatLabz this month, a new variant of the malware has been under development since September 2023. According to an analysis published by Zscaler ThreatLabz this month, a new variant of the malware has been under development since September 2023.

Researchers Santiago Vicente and Ismael Garcia Perez stated that “the new version of Zloader made significant changes to the loading module, adding RSA encryption, updating the sector generation algorithm, and for the first time compiling for 64-bit Windows operating systems.”

ZLoader, also known as Terdot, DELoader or Silent Night, is a derivative of the Zeus banking trojan that first appeared in 2015, before turning into a loader for subsequent shipments, including ransomware.

Typically distributed through phishing emails and malicious search engine ads, ZLoader suffered a major blow when a group of companies led by Microsoft's Digital Crimes Unit (DCU) gained control of 65 domains used to control and communicate with infected computers.

The latest versions of the malware, detected as 2.1.6.0 and 2.1.7.0, include junk code and string obfuscation to resist analysis attempts. Each ZLoader object is also expected to have a specific filename to execute on the compromised computer.

See also: New JinxLoader distributes Formbook and XLoader malware

Researchers noted that this may avoid malware sandboxes that rename sample files.

64-bit Windows

In addition to encrypting the static configuration using RC4, with a hardcoded alphanumeric key to hide information about the campaign name and command and control (C2) servers, the malicious code has been observed to rely on an updated version of the domain name generator algorithm as a back-up measure in case the main C2 servers are inaccessible.

The backup communication method was first observed in ZLoader version 1.1.22.0, which was spread as part of scam campaigns detected in March 2020.

The development comes as Red Canary warned of an increase in the volume of campaigns exploiting MSIX files to spread malware, such as NetSupport RAT, ZLoader , and FakeBat (also known as EugenLoader), since July 2023, in order to force Microsoft to disable the protocol handler by default at the end of December 2023.

We are also seeing the emergence of new families of thief malware, such as Rage Stealer and Monster Stealer, which are used as an outlet for information theft and as a launching pad for more serious cyberattacks.

See also: AsyncRAT malware targets US infrastructure

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How can one protect themselves from Remote Access Trojans?

The first and most important way to protect yourself from Remote Access Trojans is to use reliable security software. This should include a strong antivirus and a firewall that will prevent Trojans your system.

Second, it's important to keep your operating system and all your applications up to date. Updates often include security fixes that can close holes that attackers exploit.

Third, you should be careful with the emails and attachments you receive. Many Trojans are spread through seemingly harmless emails that contain attachments or links.

Finally, it is important to be careful when downloading files from the internet. Always check the source of the file and avoid downloading files from untrusted sources.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS