IBM Security X-Force is reporting on a new type of information-stealing malware, codenamed CoreBot, that its security researchers came across while studying malware activity on enterprise endpoints.

These enterprise endpoints are protected by IBM Trusteer Advanced Malware Protection, which allowed security engineers to intercept and stop this new type of threat.
In-depth analysis of a CoreBot attack
According to their findings, the infiltration is carried out via a dropper agent, which upon reaching the victim’s computer, executes, starting “a svchost process to write the malware file to disk and then run it.”
This process also generates a globally unique identifier (GUID), which is used “to determine its persistence via a Run key in the Windows Registry.”
At this stage, only the main CoreBot module is present on the victim's computer.
This core module communicates via randomly generated fields to command-and-control (C&C) servers, immediately after the registry key is set, requesting instructions.
The C&C server will then provide it with new commands, and the plugins to perform those tasks.
CoreBot can download other malware and even update itself.
"Using Windows PowerShell, Microsoft's task automation and configuration management framework, CoreBot can fetch other malware from the Internet, download it, and execute it on infected PCs," IBM researchers say.
The same process is also used by CoreBot to update itself.
In most cases observed by the IBM team, CoreBot targets sensitive information on the victim's computer using a plugin called Stealer.
This plugin was of particular interest in obtaining passwords access from browsers, FTP clients, email applications, Webmail accounts, private certificates, cryptocurrency wallets, and credentials from various other desktop software.
IBM security researchers report that CoreBot is “currently incapable of intercepting real-time data from Web browsers” and most antivirus engines detect it through generic names, such as Dynamer!ac and Eldorado.
