HomeSecurityKaspersky & Microsoft Exploited to Install Spying Trojan

Kaspersky & Microsoft Exploited to Install Spying Trojan

TrojanBookworm trojan "spies" on infected victims

A new Trojan has been detected by Palo Alto Networks, which uses the installed security software on the user's computer to side-load DLLs required to install itself.

This new Trojan was named Bookworm by Palo Alto, and it showed some similarities to the PlugX RAT.

At present Palo Altoreports that the Trojan has been detected in campaigns by APT groups operating only in Thailand.

As for its internal structure, Bookworm appears to be part of a new and increasingly popular trend of modular malware, malicious elements that slowly install themselves on the computer in multiple steps to avoid detection, while also using a remote C&C server to control the profile of the infected target.

The internal architecture of a Bookworm is simple. Several malicious DLLs are encrypted using an XOR algorithm and are contained together in a readme.txt.file

This file is then combined with pure executables and some DLLs into a self-extracting RAR file, which is in turn integrated with Smart Installer Maker, a utility that creates installation packages.

The installer produces what the hackers distribute, and when executed, it triggers the self-extracting hardware that unloads the malicious readme.txt, the clean DLLs, and the clean EXE.

After the installer completes, it also automatically launches a clean EXE that was just created. The executable starts searching for Microsoft Malware Protection (MsMpEng.exe) and Kaspersky Anti–Virus (ushata.exe) executables.

When it finds one, it side-loads the clean DLL into those executables and uses the permissions of those applications to install itself as a Microsoft.

From this point, Bookworm has all the permissions it needs to extract other modules from the readme.txt, initiate communication with the C&C server, load other modules, and send stolen data to the C&C server.

Palo Alto researchers do not mention what other modules can be loaded. What made it difficult for Palo Alto researchers in their investigation was the fact that Bookworm uses at least four different algorithms for encryption when communicating with the C&C server ( RC4, AES, XOR, LZO ).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS