HomeSecurityFIN7 hackers targeted automotive industry to distribute Anunak backdoor

FIN7 hackers targeted an automotive company to distribute the Anunak backdoor

Late last year, FIN7 hackers targeted employees of a major American automaker with spear-phishing emails, in order to infect systems with the Anunak backdoor.

hackers FIN7 Anunak backdoor

According to BlackBerry, the attack was based on living-off-the-land binaries, scripts, and libraries (LoLBas). The FIN7 hackers targeted employees with high-level privileges, luring them with links that led to a malicious URL that resembled the legitimate tool Advanced IP Scanner

BlackBerry attributed the attacks to the FIN7 hackers, noting elements that have been identified in their previous campaigns.

Attack on the American auto industry

As mentioned above, the attack began with spear-phishing emails targeting employees in the automotive industry's IT department.

The emails contained links leading to “advanced-ip-scanner[.]com”, a fake address that attempts to mimic the address of the legitimate scanner hosted at “advanced-ip-scanner.com”.

Researchers discovered that the fake website led to “myipscanner[.]com” (now offline). The visitor was then directed to apage Dropbox containing a malicious executable file ('WsTaskLoad.exe') that appeared to be the legitimate installer for Advanced IP Scanner.

When executed, the file triggered a multi-stage process, including the execution of DLLs, WAVs, and shellcode, which led to the loading and decryption of a file named “dmxl.bin.” This file contained the Anunak backdoor payload.

The researchers did not reveal the name of the American automaker that was attacked by the FIN7 hackers. They simply described it as “a large multinational automaker based in the US.”

BlackBerry said the group's attack failed to spread beyond the initial infected system. The company recommends that companies defend against phishing, which is the most common attack vector.

American automotive industry spear-phishing emails

Spear-phishing emails: Protection

To protect yourself from spear phishing emails, like the ones sent by the FIN7 hackers, you must first be able to recognize their characteristics. These emails often contain spelling errors, unspecified sender addresses, and sudden calls to action.

Additionally, users should be cautious with attachments and links contained in an email. If an email seems suspicious, it is best not to open any attachments or follow any links it contains.

It is also important to use an up-to-date antivirus program and a reliable spam filter. These tools can help detect and avoid spear phishing emails from FIN7 hackers.

Finally, education is one of the most effective ways to protect yourself from spear phishing emails. Learn more about the techniques attackers use and how you can recognize them.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS