HomeSecurityMalware poses as Palo Alto GlobalProtect and infects networks

Malware disguises itself as Palo Alto GlobalProtect and infects networks

Hackers are targeting Middle Eastern organizations with malware disguised as the legitimate Palo Alto GlobalProtect tool . The goal is to steal data and execute remote PowerShell commands to further access internal networks .

Palo Alto GlobalProtect malware

Palo Alto GlobalProtect is a legitimate security from Palo Alto Networks that provides secure VPN and is used by many organizations. It ensures that remote employees, contractors, and partners can securely access private network resources.

Its misuse for malware distribution shows that attackers are targeting companies and not random users.

See also: Iranian hackers APT33 target governments with Tickler malware

Palo Alto GlobalProtect: Enterprise VPN software as a lure

Trend Micro researchers discovered this campaign. At this time, they do not know how the malware is delivered . Considering the bait used, the attack may start with a phishing email.

The victim executes a file named “setup.exe”, which deploys a file named “GlobalProtect.exe” along with configuration files.

At this stage, a window appears that looks like a normal Palo Alto GlobalProtect installation process, but in reality, malware is loaded onto the system.

Researchers observed that the malware checks to see if it is running in a sandbox before executing its main code. It then transmits profile information about the compromised machine to the command and control (C2) server.

Also, the malware impersonating Palo Alto GlobalProtect uses AES encryption on its strings and data packets to be carried out at the C2.

See also: sedexp: A Linux malware that remained hidden for two years

The C2 address used a newly registered URL containing the string “ sharjahconnect .” So, it appears to be a legitimate VPN gateway for offices in Sharjah, United Arab Emirates.

Attackers try to combine their malicious activities with normal operations to avoid raising suspicions among victims.

Beacons sent at intervals are used to inform attackers about the status of the malware inthe post-infection phase, using the open source tool Interactsh.

The commands received from the command and control server are:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

time to reset: Stops malware operations for a specified duration.

pw: Executes PowerShell script and sends the result to the attacker's server.

pr wtime: Reads or writes a wait time to a file.

pr create-process: Starts a new process and returns the result.

pr dnld: Downloads a file from a specified URL.

pr upl: Uploads a file to a remote server.

invalid command type: Returns this message if an unrecognized or incorrect command is encountered.

Trend Micro does not know who is behind this malware distribution campaign (impersonating Palo Alto GlobalProtect), but it appears to be a highly targeted campaign.

See also: Cthulhu Stealer: New info-stealer malware targets MacOS

Malware disguises itself as Palo Alto GlobalProtect and infects networks

Organizations are urged to remain vigilant by implementing robust cybersecurity, such as regular updates , employee education on phishing risks, and comprehensive endpoint protection, to protect themselves from these sophisticated threats. Additionally, monitoring network activity for unusual behavior can help identify potential breaches early, thereby mitigating the risks associated with such malware attacks.

Finally, it is important for organizations to have a comprehensive incident response plan. In the event of a successful attack, having a well-defined and tested response plan can help limit the damage and minimize the impact on the organization's operations. This includes having backup systems in place to restore critical data in the event of loss or theft.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS