Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Shiba Inu Down By 2.03% bitcoin news
  • Lebanese Pound Exchange Rate Against Dollar Plunges to All-Time Low – Economics Bitcoin News bitcoin news
  • BTC Hovers Below $24,000 on Friday, as Crypto Markets Consolidate – Market Updates Bitcoin News bitcoin news
  • Long Liquidations Continue To Rock Market As Bitcoin Struggles To Settle Above $30,000 bitcoin news
  • Turkish Referee Flips Bitcoin at Istanbul Derby Kick-Off, Soccer Authority Launches Probe – Bitcoin News bitcoin news
  • Join The Gensokishi Online Closed Alpha For Massive Rewards bitcoin news
  • Elon Musk, Tesla, Spacex Facing $258 Billion Lawsuit for Promoting Dogecoin – Featured Bitcoin News bitcoin news
  • Collectors and Enthusiasts Can Now Turn Their Image and Likeness into Eye-popping NFTs with Onliners Metaverse bitcoin news

Researchers Warn of ‘Matanbuchus’ Malware Campaign Dropping Cobalt Strike Beacons

Posted on June 27, 2022 By root


A malware-as-a-service (Maas) dubbed Matanbuchus has been observed spreading through phishing campaigns, ultimately dropping the Cobalt Strike post-exploitation framework on compromised machines.

Matanbuchus, like other malware loaders such as BazarLoader, Bumblebee, and Colibri, is engineered to download and execute second-stage executables from command-and-control (C&C) servers on infected systems without detection.

Available on Russian-speaking cybercrime forums for a price of $2,500 since February 2021, the malware is equipped with capabilities to launch .EXE and .DLL files in memory and run arbitrary PowerShell commands.

The findings, released by threat intelligence firm Cyble last week, document the latest infection chain associated with the loader, which is linked to a threat actor who goes by the online moniker BelialDemon.

“If we look historically, BelialDemon has been involved in the development of malware loaders,” Unit 42 researchers Jeff White and Kyle Wilhoit noted in a June 2021 report. “BelialDemon is considered the primary developer of TriumphLoader, a loader previously posted about on several forums, and has experience with selling this type of malware.”

The spam emails distributing Matanbuchus come with a ZIP file attachment containing an HTML file that, upon opening, decodes the Base64 content embedded in the file and drops another ZIP file on the system.

The archive file, in turn, includes an MSI installer file that displays a fake error message upon execution while stealthily deploying a DLL file (“main.dll”) as well as downloading the same library from a remote server (“telemetrysystemcollection[.]com”) as a fallback option.

“The main function of dropped DLL files (‘main.dll’) is to act as a loader and download the actual Matanbuchus DLL from the C&C server,” Cyble researchers said, in addition to establishing persistence by means of a scheduled task.

For its part, the Matanbuchus payload establishes a connection to the C&C infrastructure to retrieve next-stage payloads, in this case, two Cobalt Strike Beacons for follow-on activity.

CyberSecurity

The development comes as researchers from Fortinet FortiGuard Labs disclosed a new variant of a malware loader called IceXLoader that’s programmed in Nim and is being marketed for sale on underground forums.

Featuring abilities to evade antivirus software, phishing attacks involving IceXLoader have paved the way for DarkCrystal RAT (aka DCRat) and rogue cryptocurrency miners on hacked Windows hosts.

“This need to evade security products could be a reason the developers chose to transition from AutoIt to Nim for IceXLoader version 3,” the researchers said. “Since Nim is a relatively uncommon language for applications to be written in, threat actors take advantage of the lack of focus on this area in terms of analysis and detection.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: ApeCoin Climbs 22% After Snoop Dogg-Eminem Bored Ape Video Launch
Next Post: Italy Data Protection Authority Warns Websites Against Use of Google Analytics

Related Posts

  • Experts Uncover New Espionage Attacks by Chinese ‘Mustang Panda’ Hackers cyber security news
  • Learn NIST Inside Out With 21 Hours of Training @ 86% OFF cyber security news
  • Taking the Risk-Based Approach to Vulnerability Patching cyber security news
  • Learn Cybersecurity with Palo Alto Networks Through this PCCSA Course @ 93% OFF cyber security news
  • Google Researchers Detail 5-Year-Old Apple Safari Vulnerability Exploited in the Wild cyber security news
  • Apple’s New Feature Will Install Security Updates Automatically Without Full OS Update cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Bitcoin’s Mathematical Monetary Policy Is Far More Predictable Than Gold and Fiat Currencies – Economics Bitcoin News
  • New Findings Shows Institutional Investors Take More Interest In Ethereum
  • Whales With 1k-10k BTC Depositing To Exchanges
  • Bitcoin Mining Operations Continue to Expand Amid the Crypto Winter, While Converting ‘Wasted Gas to Energy at Scale’ – Mining Bitcoin News
  • How Gold Continues To Prove To Be A Hedge Against Inflation

Recent Comments

No comments to show.
  • Euro Drops to 20-Year Low Against the US Dollar, Tapping $1.028 per Unit — Analyst Says Parity Is Imminent – Economics Bitcoin News bitcoin news
  • Bitcoin is Plunging, But It’s Too Early to Say Bulls Have Given Up bitcoin news
  • LibreOffice Releases Software Update to Patch 3 New Vulnerabilities cyber security news
  • 14% of Saudis Are Crypto Investors, 76% Have Less Than One Year of Experience in Cryptocurrency Investment – Featured Bitcoin News bitcoin news
  • 3 Bills Introduced in US to Make CFTC Primary Regulator of Crypto Spot Markets – Regulation Bitcoin News bitcoin news
  • Lawsuit Accuses Binance US of Selling Unregistered Securities, False Advertising Terra UST as ‘Safe’ – Bitcoin News bitcoin news
  • Localbitcoins User Pleads Guilty to Running Unlicensed Crypto Business — Faces Up to 5 Years in Prison – Regulation Bitcoin News bitcoin news
  • Daily Pump & Dump | June 2, 2022 Crypto Market Report: BTC, ETH, ICP bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme