Legitimate, but compromised websites are being used to deliver a Windows called BadSpace, disguised as fake browser updates.

"The threat actor uses an attack chain that includes a compromised website, a command and control (C2) server, fake browser updates, and a JScript downloader to install a backdoor on the victim's system," German cybersecurity firm G DATA said in a report.
See also: New Cross-Platform “Noodle RAT” Malware Targets Windows and Linux
Details of the malware were first shared by researchers kevross33 and Gi7w0rm last month. The process begins with a compromised website, including those built on WordPress, where code containing logic is inserted to determine whether a user has visited the site before.
If this is the user's first visit, information about the device, IP address, user, and location is collected and transmitted to a predefined domain via an HTTP GET request.
The response from the server then overlays the web page content with a fake Google Chrome. This either downloads the malware directly or uses a JavaScript downloader, which in turn downloads and executes BadSpace.
Read more: New phishing attack distributes More_eggs malware
An analysis of the C2 servers used in the campaign revealed that it is linked to the well-known SocGholish malware (also known as FakeUpdates). This JavaScript-based malware is distributed through the same mechanism and acts as a downloader.
BadSpace, in addition to using anti-sandbox checks and setting up persistence via scheduled tasks, has the ability to collect system information and execute commands that allow it to take screenshots, execute instructions via cmd.exe, read and write files, as well as delete scheduled projects.

Both eSentire and Sucuri have warned of various campaigns that exploit fake browser update baits on compromised websites to distribute information-stealing software and remote access trojans
See also: Turla Group: Developed two backdoors – LunarWeb and LunarMail
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
