HomeSecurityHackers abuse Google Cloud Run to distribute banking trojans

Hackers abuse Google Cloud Run to distribute banking trojans

Hackers are abusing the Google Cloud Run service to distribute banking trojans , such as Astaroth, Mekotio, and Ousaban .

Google Cloud Run banking trojans

Google Cloud Run allows users to develop services , websites or applications and easily handle workloads.

Cisco Talos researchers noticed a huge increase in Google Run abuse since September 2023. Brazilian hackers had then launched malicious campaigns using MSI installation files to deploy malware payloads.

Google Cloud Run is considered useful for cybercriminals because it is cost-effective and can bypass security.

See also: Anatsa: Android banking trojan has made its way to Google Play and is targeting more countries

How are banking trojans distributed ?

The attacks begin with phishing emails to potential victims. The emails appear to be legitimate communications for invoices, financial statements, or messages from local government and tax authorities.

According to researchers, most malicious emails are in Spanish , as they mainly target Latin American countries, but emails in Italian have also been detected .

The emails contain links that lead victims to malicious services hosted on Google Cloud Run.

In some cases, the payload is delivered via files MSI . In other cases, the service issues a 302 redirect to a Google Cloud Storage location . There, there is a ZIP archive with a malicious MSI file. When the victim executes the malicious MSI files, new malicious payloads are downloaded and executed on the system.

According to researchers, second-stage payload delivery is typically accomplished by abusing the legitimate Windows “BITSAdmin.”

Finally, the malware establishes persistence on the victim's system by adding LNK files ('sysupdates.setup<random_string> .lnk') in the Startup folder, configured to execute a PowerShell command that executes the infection script ('AutoIT').

See also: Coyote banking trojan has infected 61 banking applications

Google Cloud Run hackers

Abuse of Google Cloud Run to distribute banking trojans

Recent campaigns abusing Google Cloud Run include three banking trojans: Astaroth/Guildma, Mekotio, and Ousaban. Through the above processes, the malware secretly infiltrates systems , establishes persistence, and steals financial data that can be used for illegal transactions and theft of victims’ money.

The Astaroth trojan also features advanced evasion techniques. It initially focused on victims in Brazil, but now targets over 300 financial institutions in 15 Latin American countries. Recently, the malware has also started collecting credentials for cryptocurrency.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Mekotio also targets the Latin American region . It is known for stealing banking credentials and personal information and performing fraudulent transactions. It can also manipulate web browsers to redirect users to phishing sites.

The Ousaban banking trojan performs keylogging, captures screenshots, and steals credentials, using cloned banking pages.

Cisco Talos notes that Ousaban is delivered at a later stage in the Astaroth infection chain.

See also: Mispadu banking trojan: Exploits Windows SmartScreen vulnerability

Google was informed about the abuse of Cloud Run to distribute banking trojans and, according to statements made to Bleeping Computer, it removed the malicious links and is looking for ways to strengthen security and prevent similar attacks.

Astaroth

Protection from banking trojans

To protect yourself from Banking Trojans, such as Astaroth, Mekotio, and Ousaban, it is vital to software security your device's. This includes installing the latest updates and patches provided by the manufacturer of the operating system and security software.

Additionally, it is important to use a reliable antivirus and anti-malware program . should This providereal-time protection and be able to detect and remove Banking Trojans.

See also: 10 new Android banking trojans appeared in 2023

You should also be careful with the emails and messages you receive. Many Banking Trojans are spread through phishing emails that try to trick users into clicking on dangerous links.

Finally, avoid downloading apps that look suspicious. If they ask for more permissions than they need to function properly, don't download them to your device.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS