HomeSecurityBoolk hackers distribute new BMANAGER malware

Boolk hackers distribute new BMANAGER malware

Security researchers at Group-IB have uncovered the malicious activities of a new hacking group (Boolka), which is engaged in the development of sophisticated malware (BMANAGER) and web attacks.

Boolk hackers

According to a recent report from the company, the group has been exploiting vulnerabilities through SQL injection attacks since at least 2022. In fact, researchers have observed that Boolk hackers are targeting websites in various countries. The malicious scripts injected into these websites are designed to steal data.

In January 2024, Group-IB analysts discovered a hacker Boolkthat distributed the BMANAGER Trojan. This discovery led to the disclosure of Boolk's malware delivery platform, which leverages the BeEF framework.

See also: Chinese hackers distribute SpiceRAT and SugarGh0st malware

The platform uses a modified Django. The malicious JavaScript, injected by the Boolka hackers, intercepts user inputs from infected websites and steals sensitive information, such as passwords and usernames. It then sends this information to the attackers' server.

Researchers also observed that the Boolk group is constantly evolving its techniques. In late 2023, its payloads were improved to include new controls and features, such as creating hidden elements on web pages to avoid detection.

Further investigation revealed several domain names used to distribute malware. As of March 2024, Boolk’s malware delivery platform was actively distributing the BMANAGER Trojan. This malware can perform a range of malicious activities, including data extraction, keystroke logging, and file theft.

See also: Fickle malware: Uses PowerShell to bypass UAC and extract data

BMANAGER includes various components, such as BMREADER, BMLOG, BMHOOK, and BMBACKUP. Each module has a specific function, and together they collectively enhance the hackers to extract valuable information from infected systems.

BMANAGER malware

This particular campaign highlights the importance of everyone being cautious of strange sites we come across online. Malware serve as a reminder that cyber threats are constantly evolving and becoming more sophisticated. As users, it is important to stay informed and take the necessary precautions to protect ourselves.

Additionally, to defend against the BMANAGER Trojan and similar threats, organizations should keep their systems and applications up to date, use advanced protection, monitor network traffic , and employ intrusion detection systems. Also, training employees on phishing and safe browsing practices is essential to avoid such attacks.

See also: Evasive SquidLoader Malware Targets Chinese Organizations

As technology evolves, so do the tactics used by cybercriminals. Staying informed about potential threats and taking the necessary precautions can help keep your device and personal information safe.

Source: www.infosecurity-magazine.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS