HomeSecurityVariants of Bartalex distribute Pony & Dyre Malwares

Bartalex Variants Spread Pony & Dyre Malwares

Some strains of the Bartalex malware, a macro-based malware that first appeared earlier in time, was recently detected distributing the Pony loader malware and the banking Trojan Dyre. It spreads mainly via spam, the first traces of Bartalex were observed in March embedded in macros of Microsoft Word and Excel.

Macros the case with malware, what's old is new again. Microsoft's Malware Protection Center raised the alarm about the increase in attacks and the alarming increase in macro threats as recently as January.

Mr. Brad Duncan, a security researcher at Rackspace, detected Bartalex via a rigged Word document on Tuesday.

This Word document appears to come from an ADP payroll service. As Mr. Duncan notes, a quick glance at the subject line of the email shows that the email in question does not actually come from ADP, and if the user opens the file, assuming it contains embedded macros that are enabled in the Word document, they will execute all the linked macros.

Bartalex Variants Spread Pony & Dyre Malwares

According to Mr. Duncan, who used a network protocol analyzing tool to review traffic for malware, he found evidence of Pony and Dyre in this version of Bartalex.
Using Wireshark, Duncan observed “certificate data found in SSL traffic originating from Dyre” in the code , and on Security Onion he detected a number of “events related to Bartalex and the Pony downloader.”

The Pony Trojan, which has been circulating in recent years, is known for its activity as a thief of Bitcoin, passwords and other credentials, but perhaps the most not-so-well-known of its roles is that of a downloader. The Trojan primarily downloads other malicious software, often such as Gameover Zeus, onto the machines it affects.

While Bartalex has been observed to be associated with Dyre previously, this case appears to be the first time Pony is used for this purpose.

Analysts have observed that attackers have been spreading Bartalex via thousands of infected malicious Dropbox links since April of this year. The malware downloads various variants of Dyre, a banking malware that specializes in targeting user account credentials, onto the machines it infects.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS