HomeSecurityCybercriminals abuse Stack Overflow to distribute malware

Cybercriminals are abusing Stack Overflow to distribute malware

Cybercriminals are abusing Stack Overflow, answering user and promoting a malicious PyPi package that installs info-stealer malware on Windows systems.

Stack Overflow malware

Sonatype researcher Ax Sharmadiscovered that this malicious PyPi package is part of an older campaign (Cool package) that targeted Windows last year.

The new malware package is called "pytoileur" and was uploaded to the PyPi repository over the weekend, claiming to be an API management tool.

Malicious packages like this one are often promoted using names similar to other popular packages. This technique is called typo-squatting.

See also: New malware targets ATMs in Europe

However, in this particular case, cybercriminals took a novel approach, answering questions on Stack Overflow and promoting the malware package as a solution.

As Stack Overflow is a popular platform for developers, where many questions are asked and various issues are solved, cybercriminals found the opportunity to exploit it to spread malware by making it look like programming interfaces or libraries.

“We further noticed that a StackOverflow account, “EstAYA G”, created about 2 days ago is now exploiting platform community members seeking help with debugging, directing them to install this malicious package as a “solution” to their problem even though the “solution” is unrelated to the questions posted by the developers,” Sharma explained in report .

The pytoileur package contains a 'setup.py' file that fills a base64 encoded command to be executed with spaces so that it is hidden (unless word wrapping is enabled in the IDE or text file editor).

Stack Overflow cybercriminals

The command will download an executable file named "runtime.exe" from a remote location and execute it.

See also: Transparent Tribe: Deploys Python, Golang and Rust malware on Indian targets

This executable file is actually a Python program that is converted to .exe and acts as info-stealer malware to steal cookies, passwords ,browser history, credit cards, and other data.

All this information is sent to cybercriminals, who can use it to carry out additional attacks or sell it to other hackers.

We have seen malicious PyPi packages used many times in malware campaigns, but this approach by cybercriminals, where they respond to Stack Overflow to offer supposed solutions, is a very interesting approach.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

One of the main reasons why hackers can abuse Stack Overflow in this way is open nature . Anyone can create an account and post questions or answers, making it easy for malicious actors to band together and spread their malware.

Additionally, the large community on Stack Overflow means that there is always a significant number of users online, increasing the chances of someone falling victim to these attacks.

To protect themselves from these attacks, users should be cautious when running code or installing packages on Stack Overflow. They should thoroughly examine the code and research the package before trusting it. In addition, users can also enable strict security in their browsers to prevent any malicious downloads.

See also: CERT-UA warned of malware campaign from UAC-0006

In conclusion, the misuse of Stack Overflow by cybercriminals to spread malware is a worrying trend. It highlights the need for users to be cautious when using online platforms, even those considered trustworthy and legitimate. It also emphasizes the importance of being informed about cybersecurity best practices and implementing the necessary precautions to protect against such attacks. 

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS