A new variant of RomCom malware, named SnipBot, infiltrates networks and steals data from compromised systems.

SnipBot was discovered by researchers at Palo Alto Networks' Unit 42, after analyzing a DLL module used in these attacks.
The latest SnipBot campaigns target various sectors, including IT services, legal services, and agriculture.
RomCom malware
RomCom is a backdoor that has been used to deliver the Cuba ransomware, as well as for targeted phishing.
Its previous version, dubbed RomCom 4.0 by Trend Micro researchers, included various capabilities, including command execution, file theft, installation of new malicious payloads, modification of the Windows registry, and use of the TLS protocol for command and control (C2) communications.
See also: White Snake: Steals CVC credit card codes in Chrome
Researchers believe the new SnipBot version is RomCom 5.0 and uses 27 commands. These commands give attackers more granular control over data-stealing operations, allowing them to target specific file types or directories, compress stolen data using the 7-Zip archiver, and insert archive payloads that will be extracted to the host computer.
Additionally, SnipBot uses advanced obfuscation techniques to avoid detection.
The main SnipBot module, “single.dll”, is stored in encrypted form in the Windows Registry from where it is loaded into memory. Additional modules downloaded from the C2 server, such as “keyprov.dll”, are decrypted and executed in memory as well.
Unit 42 researchers analyzed VirusTotal, which allowed them to discover the original infection vector.
The attack usually begins with phishing emails that contain links to download seemingly harmless files, such as PDF documents.
Also, a fake Adobe website was used in the past where the victim was supposed to download a font to be able to read the attached PDF file.
One way or another, a series of redirects to multiple domains under the attacker's control (“fastshare[.]click”, “docstorage[.]link” and “publicshare[.]link” is triggered. Finally, a malicious executable downloaded from file-sharing platforms, such as “temp[.]sh”, is installed.
See also: Ajina.Banker: New Android malware steals financial data
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Downloaders are often signed with legitimate certificates so that securitywhen retrieving DLL executables from the C2.
A common tactic for loading these payloads is to use COM hijacking to insert them into “explorer.exe”.
After compromising a system and infecting it with the SnipBot malware, the attacker collects information about the corporate network and domain controller. It then steals specific file types from the Documents, Downloads, and OneDrive.
Researchers say a second phase of discovery is coming, with the AD Explorer utility allowing viewing and editing of Active Directory (AD) as well as navigating the AD database.
The targeted data is extracted using the PuTTY Secure Copy client, after archiving it with WinRAR.

Protection from info-stealer malware
Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.
See also: StealC malware: Abuse of browser kiosk mode to steal credentials
It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.bleepingcomputer.com
