HomeSecurityHackers exploit legitimate sites to distribute BadSpace Windows Backdoor

Hackers exploit legitimate sites to distribute BadSpace Windows Backdoor

Legitimate, but compromised websites are being used to deliver a Windows called BadSpace, disguised as fake browser updates.

Badspace

"The threat actor uses an attack chain that includes a compromised website, a command and control (C2) server, fake browser updates, and a JScript downloader to install a backdoor on the victim's system," German cybersecurity firm G DATA said in a report.

See also: New Cross-Platform “Noodle RAT” Malware Targets Windows and Linux

Details of the malware were first shared by researchers kevross33 and Gi7w0rm last month. The process begins with a compromised website, including those built on WordPress, where code containing logic is inserted to determine whether a user has visited the site before.

If this is the user's first visit, information about the device, IP address, user, and location is collected and transmitted to a predefined domain via an HTTP GET request.

The response from the server then overlays the web page content with a fake Google Chrome. This either downloads the malware directly or uses a JavaScript downloader, which in turn downloads and executes BadSpace.

Read more: New phishing attack distributes More_eggs malware

An analysis of the C2 servers used in the campaign revealed that it is linked to the well-known SocGholish malware (also known as FakeUpdates). This JavaScript-based malware is distributed through the same mechanism and acts as a downloader.

BadSpace, in addition to using anti-sandbox checks and setting up persistence via scheduled tasks, has the ability to collect system information and execute commands that allow it to take screenshots, execute instructions via cmd.exe, read and write files, as well as delete scheduled projects.

Badspace backdoor

Both eSentire and Sucuri have warned of various campaigns that exploit fake browser update baits on compromised websites to distribute information-stealing software and remote access trojans

See also: Turla Group: Developed two backdoors – LunarWeb and LunarMail

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS