Fake installations of Adobe Acrobat Readerare spreading new malware called Byakugan.

The starting point of the attack is a PDF written in Portuguese, which, when opened, shows a blurry image and asks the victim to click on a link to download the Reader app to view the content.
Read more: Adobe: Adds AI assistant to Acrobat and Reader
According to Fortinet FortiGuard Labs, clicking on a URL leads to the download of an installer (“Reader_Install_Setup.exe”) that triggers the infection sequence. Details of the campaign were first revealed by AhnLab Security Intelligence Center (ASEC) last month.
The attack chain uses various techniques, including DLL hijacking and Windows User Access Control (UAC) bypass , to load a malicious dynamic link library (DLL) file named “BluetoothDiagnosticUtil.dll.” This file drops a malicious program when loaded. It also creates a legitimate installer for a PDF reader, such as Wondershare PDFelement.
The binary is designed to collect and distribute system metadata to a command and control (C2) server, and drop the main module (“chrome.exe”) on a different server that also acts as a C2 to receive files and commands.
“Byakugan is a node.js-based malware that is packaged into its executable by pkg,” said security researcher Pei Han Liao. “In addition to the main script, there are several libraries that correspond to features.”
See also: ANY.RUN Sandbox: Allows SOC and DFIR teams to analyze advanced Linux malware
This includes monitoring the victim's desktop using OBS Studio, taking screenshots, mining cryptocurrency, logging keystrokes, enumerating and uploading files, and collecting data stored in web browsers.
“The use of both clean and malicious elements in malware is showing an alarming increase, with Byakugan being no exception,” Fortinet. “This approach increases the amount of noise generated during analysis, making accurate detections more difficult.”
ASEC has announced a new campaign that exposes the Rhadamanthys information extractor via a pre-designed groupware installer .
“The threat actor created a fake website that looks like the original, exposing it to users through search engine ads,” the South Korean cybersecurity firm said. “The distributed malware uses the indirect syscall technique to remain invisible to defense systems.”

See also: Hackers distribute USB malware via websites
Additionally, it has been discovered that unidentified threat actors are using a modified version of Notepad++ to spread the WikiLoader malware (also known as WailingCrab).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
