HomeSecurityHackers abuse antivirus updates to distribute GuptiMiner malware

Hackers abuse antivirus updates to distribute GuptiMiner malware

North Korean hackers are exploiting the update mechanism of the eScan antivirus and are attempting to create backdoors in large corporate networks and deliver cryptocurrency miners via the GuptiMiner malware.

North Korean hackers

Avast researchers describe GuptiMiner as “a highly sophisticated threat” since it can do many things, such as perform DNS requests to the attacker’s DNS servers, extract payloads from images, sign its payloads, and perform DLL sideloading.

eScan updates deliver GuptiMiner malware

According to Avast, the hackers behind GuptiMiner are carrying out an adversary-in-the-middle (AitM) attack to hijack the regular virus definition update package and replace it with a malicious called "updll62.dlz".

The malicious file includes the necessary antivirus updates as well as the GuptiMiner malware, as a DLL file named "version.dll".

See also: 2023: Over 10 million devices infected with info-stealer malware

The eScan updater processes the package normally and eventually executes it. During this stage, the DLL is sideloaded from the legitimate eScan binaries, giving the malware system-level permissions . The DLL then retrieves other malicious payloads from the hackers ’ infrastructure , establishes persistence on the host, performs DNS manipulation, injects shellcode into legitimate processes, uses code virtualization, stores payloads in the Windows registry , and extracts PE from PNGs .

Additionally, the GuptiMiner malware checks if the system it is running on has more than 4 CPU cores and 4 GB of RAM to avoid sandbox environments. It also checks if Wireshark, WinDbg, TCPView, 360 Total Security, Huorong Internet Security, Process Explorer, Process Monitor, and OllyDbg.

Finally, the malware has the ability to disable AhnLab and Cisco Talos products.

Avast researchers believe that the GuptiMiner malware may be linked to the North Korean hackers Kimsuki, as they have identified some similarities in the way the campaigns operate. One common element is the use of the domain mygamesonline[.]org, which has also been observed in the operations of the Kimsuki hackers.

eScan

GuptiMiner malware deploys other malware on compromised systems

Through GuptiMiner, hackers are also deploying other malware on compromised systems, including two backdoors and the well-known XMRig Monero miner.

See also: GitHub comments are being abused to promote malware

The first backdoor scans local networks to detect vulnerable systems for lateral movement. The second is a complex modular malware that scans the host computer for stored private keys and cryptocurrency. It can accept commands to install additional modules in the registry, further enhancing its capabilities in infected environments. However, Avast did not provide additional details.

As for the XMRig miner, its use could be an attempt to divert attention from the main line of attack.

Avast researchers revealed the eScan vulnerability used by hackers, and the provider confirmed that the problem has been resolved.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, Avast says it continues to see new infections with the GuptiMiner malware, meaning some users have not updated eScan.

GuptiMiner malware
North Korean hackers abuse antivirus updates to distribute GuptiMiner malware

General malware protection

The first and most important step in protecting yourself from malware is to install reliable antivirus software. This software should be able to detect, isolate, and remove malware before it can cause damage to your computer.

See also: Malware campaign traps and blackmails child exploiters

However, as we have seen, attackers are even exploiting antiviruses (e.g. GuptiMiner malware). Therefore, it is important to keep your operating system and all applications, including your antivirus, up-to-date. These updates include security patches that fix vulnerabilities.

Avoid visiting suspicious websites or downloading files from untrusted sources. These activities can expose your computer to the risk of malware infection.

Finally, it is important not to open unsolicited or suspicious emails. These emails may contain malware or direct you to websites that host malware.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS