HomeSecurityMintsLoader distributes GhostWeaver via Phishing, ClickFix

MintsLoader distributes GhostWeaver via Phishing, ClickFix

The malware loader called MintsLoader has been used to deliver a remote PowerShell-based trojan known as GhostWeaver . Phishing and drive-by download campaigns distributing MintsLoader have been detected since early 2023, according to Orange Cyberdefense .

MintsLoader GhostWeaver Phishing

See also: Phishing campaign targets WooCommerce administrators

The loader has been observed delivering various malicious payloads, including StealC and a modified version of the BOINC (Berkeley Open Infrastructure for Network Computing) client . The malware has also been used by cybercriminals operating e-crime services such as SocGholish (also known as FakeUpdates) and LandUpdate808 (also known as TAG-124) , who distribute the payloads via phishing emails targeting the industrial, legal, and energy sectors, as well as via fake browser update prompts.

In a notable development, recent waves of attacks are leveraging an increasingly common social engineering technique called ClickFixto trick website visitors into copying and executing malicious JavaScript and PowerShell code. Links to ClickFix pages are distributed via spam emails.

See also: New phishing emails imitate Google to steal credentials

These features, combined with blocking and obfuscation techniques, allow cybercriminals to make analysis difficult and complicate threat detection. The main role of the malware is to download the next stage of the malicious payload from a domain generated via DGA (Domain Generation Algorithm), using a PowerShell script over HTTP.

MintsLoader distributes GhostWeaver via Phishing, ClickFix
MintsLoader distributes GhostWeaver via Phishing, ClickFix

GhostWeaver , according to a report by TRAC Labs in February, is designed to maintain persistent communication with the command and control (C2) server, create DGA domains based on a fixed seed algorithm that uses the week and year, and deliver additional malicious payloads in the form of plugins that can intercept data from browsers and modify HTML content .

This revelation comes as Kroll disclosed that threat actors are attempting to gain initial access through an ongoing campaign codenamed CLEARFAKE , which leverages the ClickFix technique to trick victims into executing MSHTA commands, which ultimately install the Lumma Stealer malware .

See also: Beware – phishing email passes Google and Gmail checks

A related point is that techniques such as Domain Generation Algorithm (DGA) make it extremely difficult to detect and block communication with C2 servers. DGA domains are constantly changing and dynamically created, meaning that traditional filtering methods such as blacklisting are not sufficient. Furthermore, the use of tools such as PowerShell and MSHTA is a popular tactic for bypassing antivirus, as these are legitimate Windows tools that, when used maliciously, often go undetected.

Source: thehackernews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS