Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News bitcoin news
  • Why Are GameFi Projects Crucial Contributors To Crypto Adoption? bitcoin news
  • Proposed Crypto Mining Ban in Norway Fails to Gain Support in Parliament – Mining Bitcoin News bitcoin news
  • Here’s How to Purchase Your First NFT Domain on Quik․com – Sponsored Bitcoin News bitcoin news
  • Ethereum Miners Surpass Bitcoin Miner Revenue By $224M bitcoin news
  • Warren Buffett Won’t Pay $25 for All Bitcoin in the World — Charlie Munger Calls BTC ‘Stupid and Evil’ – Featured Bitcoin News bitcoin news
  • California Governor Newsom Signs Executive Order on Crypto, Blockchain, and Web3 – Regulation Bitcoin News bitcoin news
  • Lido (LDO) Sheds 58% Of Its All-Time High TVL At $11 Billion bitcoin news

Hackers Using PrivateLoader PPI Service to Distribute New NetDooka Malware

Posted on May 6, 2022 By root


A pay-per-install (PPI) malware service known as PrivateLoader has been spotted distributing a “fairly sophisticated” framework called NetDooka, granting attackers complete control over the infected devices.

“The framework is distributed via a pay-per-install (PPI) service and contains multiple parts, including a loader, a dropper, a protection driver, and a full-featured remote access trojan (RAT) that implements its own network communication protocol,” Trend Micro said in a report published Thursday.

PrivateLoader, as documented by Intel 471 in February 2022, functions as a downloader responsible for downloading and installing additional malware onto the infected system, including SmokeLoader, RedLine Stealer, Vidar, Raccoon, GCleaner, and Anubis.

Featuring anti-analysis techniques, PrivateLoader is written in the C++ programming language and is said to be in active development, with the downloader malware family gaining traction among multiple threat actors.

PrivateLoader infections are typically propagated through pirated software downloaded from rogue websites that are pushed to the top of search results via search engine optimization (SEO) poisoning techniques.

“PrivateLoader is currently used to distribute ransomware, stealer, banker, and other commodity malware,” Zscaler noted last week. “The loader will likely continue to be updated with new features and functionality to evade detection and effectively deliver second-stage malware payloads.”

The framework, still in its development phase, contains different modules: a dropper, a loader, a kernel-mode process and file protection driver, and a remote access trojan that uses a custom protocol to communicate with the command-and-control (C2) server.

The newly observed set of infections involving the NetDooka framework commences with PrivateLoader acting as a conduit to deploy a dropper component, which then decrypts and executes a loader that, in turn, retrieves another dropper from a remote server to install a full-featured trojan as well as a kernel driver.

“The driver component acts as a kernel-level protection for the RAT component,” researchers Aliakbar Zahravi and Leandro Froes said. “It does this by attempting to prevent the file deletion and process termination of the RAT component.”

The backdoor, dubbed NetDookaRAT, is notable for its breadth of functionality, enabling it to run commands on the target’s device, carry out distributed denial-of-service (DDoS) attacks, access and send files, log keystrokes, and download and execute additional payloads.

This indicates that NetDooka’s capabilities not only allow it to act as an entry point for other malware, but can also be weaponized to steal sensitive information and form remote-controlled botnets.

“PPI malware services allow malware creators to easily deploy their payloads,” Zahravi and Froes concluded.

“The use of a malicious driver creates a large attack surface for attackers to exploit, while also allowing them to take advantage of approaches such as protecting processes and files, bypassing antivirus programs, and hiding the malware or its network communications from the system.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: The Nightly Mint: Daily NFT Recap
Next Post: The Popularity of Crypto Online Gambling in Canada

Related Posts

  • Malicious NPM Packages Target German Companies in Supply Chain Attack cyber security news
  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • New Chaos Ransomware Builder Variant “Yashma” Discovered in the Wild cyber security news
  • U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware cyber security news
  • Researchers Warn of “Eternity Project” Malware Service Being Sold via Telegram cyber security news
  • Critical TLStorm 2.0 Bugs Affect Widely-Used Aruba and Avaya Network Switches cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys
  • ETH Back Under $2,000 as Balenciaga Gains Lose Steam – Market Updates Bitcoin News

Recent Comments

No comments to show.
  • How Scalable Quantum-Safe Blockchains Help Against Network Outages bitcoin news
  • Bitcoin Recovers Above $30,000, Has The Bottom Been Marked? bitcoin news
  • EU Proposes New Rules for Tech Companies to Combat Online Child Sexual Abuse cyber security news
  • A Story of Incredible Belief….. How GAIMIN Gladiator’s Acquired Team Tickles! – Sponsored Bitcoin News bitcoin news
  • Mykola Udianskyi Wins “Best Digital Currency Influencer 2022” at WIBA Awards in Cannes bitcoin news
  • How STACKD Finance Services Make DeFi Safer for Everyone – Sponsored Bitcoin News bitcoin news
  • Algoracle Announces $1․5 Million Seed Round – Press release Bitcoin News bitcoin news
  • Authorities Seize Over 1,500 Crypto Mining Rigs in Dagestan Crackdown – Mining Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme