HomeSecurityNew variant of Neverquest Trojan targets North America

New variant of Neverquest Trojan targets North America

An updated version of the Neverquest Trojan discovered in November primarily targets North American users and secondarily users from Europe and Asia.

New Neverquest Trojan

Researchers found that the latest variant of the threat, which is also known as Vawtrack, is being spread via various malware droppers including Zemot.

Zemot is part of the Upatre family , which has been used repeatedly by the operators of the Asprox / Kuluoz botnet to funnel more malware to already infected computers.

Security researchers at IBM 's Trusteer noticed that the latest version of Neverquest includes a modified installation process and communication with the C&C servers is now done via the Tor2web network.

By placing servers on Tor, cybercriminals protect their operation as connections within the network are encrypted and remain anonymous.

Ilya Kolmanovich, an engineer at Trusteer, notes in a blog post that the new Neverquest is also being spread via exploit kits in drive-by attacks .

The modification of the attack process is completed in two stages. The first consists of writing the malicious DLL payload to the %temp% folder , while the second executes it with the command line tool “ regsvr32.exe ”.

After the file is executed, a large number of Windows processes are “infected” with malicious code and the dropper is deleted from the system.

Kolmanovich says that the latest strain of Neverquest relies on a “recurring key” technique to achieve persistence and immunity from malware removal by antivirus. This is done by continuously registering itself in the Windows registry.

Another technique observed is called a "watchdog" and is designed for the critical DLL module. This is reproduced immediately after its termination by other injected processes.

Neverquest 2

The new sample also has enhanced capabilities, such as the ability to record videos and capture screenshots. In addition, a Pony module, the purpose of which is to intercept credentials stored in the browser, as well as the keys of email clients and FTP programs.

It appears that the latest version of the threat currently includes a list of 300 targets worldwide, but not all of them belong to the financial sector. Some targets are related to gambling, social networks , and media, which is a clear sign that the scammers are “hunting” for any information that can be used to make money.

Regarding protection against Neverquest, Kolmanovich says, “Security products that take a simplistic approach will be bypassed with every change that Neverquest implements until the new modification is studied. Until then, these products are ineffective.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS