HomeSecuritySocGholish Malware: Exploits the BOINC project to carry out cyberattacks

SocGholish Malware: Exploits the BOINC project to carry out cyberattacks

JavaScript malware , also known as SocGholish malware, is used to install a remote trojan called AsyncRAT, as well as the legitimate open-source project BOINC .

SocGholish malware

BOINC (Berkeley Open Infrastructure Network Computing Client) is an open-source "volunteer computing" platform maintained by the University of California. Its purpose is to implement high-performance distributed computing on a large scale, using home computers on which the application is installed.

See more: Check Point: Exploiting compiled V8 JavaScript by malware creators

“This resembles a cryptocurrency miner, in that it uses the computer’s resources to perform tasks. In reality, it is designed to reward users with a specific type of cryptocurrency, Gridcoin, created for this purpose,” Huntress researchers Matt Anderson, Alden Schmidt and Greg Linares said in a report published last week.

This malware connects to domains controlled by cybercriminals (“rosettahome[.]cn” or “rosettahome[.]top”), acting as command and control (C2) servers. Through them, data is collected from the hosts, payloads are transmitted, and additional commands are executed. As of July 15, 10,032 clients are connected to these two domains.

The cybersecurity firm said that while it has not observed any subsequent activity or execution of tasks from the infected computers, it hypothesizes that “the host connections could be sold as initial access, which would be used by other hackers and possibly to execute ransomware.”

SocGholish malware cyberattacks typically begin when users visit compromised websites, where they are prompted to download a fake browser update. Running this update triggers the download of additional malicious payloads on affected systems. In this case, the JavaScript downloader triggers two parallel chains: one leads to the installation of an intangible variant of AsyncRAT, while the other ends up installing BOINC.

Read more: New JavaScript malware targets banks worldwide

The BOINC application, which is renamed to “SecurityHealthService.exe” or “trustedinstaller.exe” to avoid detection, ensures persistence through a scheduled task using a PowerShell script. The malicious use of BOINC for malicious purposes has not escaped the attention of the project maintainers, who are investigating the issue and looking for solutions to address this malware. The first evidence of misuse dates back to at least June 26, 2024.

“The motivation and intent of the threat actor that installed this software on infected hosts remain unclear,” the researchers said. “Infected clients that actively connect to malicious BOINC servers are at serious risk, as threat actors may exploit this connection to execute malicious commands or software on the host. This could lead to privilege escalation or parallel traffic within the network, compromising an entire domain.”

SocGholish malware

This development comes as Check Point reported that hackers are using the V8 JavaScript compiler to bypass static detections and hide remote access trojans, stealers, loaders, cryptocurrency miners, wipers and ransomware. “In the eternal struggle between security experts and threat actors, the SocGholish malware operators continue to invent new techniques to hide their attacks,” said security Moshe Marelus.

See more: Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware

no surprise that they started using V8, as this technology is widespread and extremely difficult to analyze.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS