HomeSecuritySnipBot: New version of RomCom malware steals data

SnipBot: New version of RomCom malware steals data

A new variant of RomCom malware, named SnipBot, infiltrates networks and steals data from compromised systems.

SnipBot RomCom malware

SnipBot was discovered by researchers at Palo Alto Networks' Unit 42, after analyzing a DLL module used in these attacks.

The latest SnipBot campaigns target various sectors, including IT services, legal services, and agriculture.

RomCom malware

RomCom is a backdoor that has been used to deliver the Cuba ransomware, as well as for targeted phishing.

Its previous version, dubbed RomCom 4.0 by Trend Micro researchers, included various capabilities, including command execution, file theft, installation of new malicious payloads, modification of the Windows registry, and use of the TLS protocol for command and control (C2) communications.

See also: White Snake: Steals CVC credit card codes in Chrome

Researchers believe the new SnipBot version is RomCom 5.0 and uses 27 commands. These commands give attackers more granular control over data-stealing operations, allowing them to target specific file types or directories, compress stolen data using the 7-Zip archiver, and insert archive payloads that will be extracted to the host computer.

Additionally, SnipBot uses advanced obfuscation techniques to avoid detection.

The main SnipBot module, “single.dll”, is stored in encrypted form in the Windows Registry from where it is loaded into memory. Additional modules downloaded from the C2 server, such as “keyprov.dll”, are decrypted and executed in memory as well.

Unit 42 researchers analyzed VirusTotal, which allowed them to discover the original infection vector.

The attack usually begins with phishing emails that contain links to download seemingly harmless files, such as PDF documents.

Also, a fake Adobe website was used in the past where the victim was supposed to download a font to be able to read the attached PDF file.

One way or another, a series of redirects to multiple domains under the attacker's control (“fastshare[.]click”, “docstorage[.]link” and “publicshare[.]link” is triggered. Finally, a malicious executable downloaded from file-sharing platforms, such as “temp[.]sh”, is installed.

See also: Ajina.Banker: New Android malware steals financial data

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Downloaders are often signed with legitimate certificates so that securitywhen retrieving DLL executables from the C2.

A common tactic for loading these payloads is to use COM hijacking to insert them into “explorer.exe”.

After compromising a system and infecting it with the SnipBot malware, the attacker collects information about the corporate network and domain controller. It then steals specific file types from the Documents, Downloads, and OneDrive.

Researchers say a second phase of discovery is coming, with the AD Explorer utility allowing viewing and editing of Active Directory (AD) as well as navigating the AD database.

The targeted data is extracted using the PuTTY Secure Copy client, after archiving it with WinRAR.

SnipBot: New version of RomCom malware steals data

Protection from info-stealer malware

Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.

See also: StealC malware: Abuse of browser kiosk mode to steal credentials

It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS