HomeCyber BalkansHackers Exploit Ethereum Smart Contracts to Conceal Amatera Stealer C2 Servers

Hackers Exploit Ethereum Smart Contracts to Conceal Amatera Stealer C2 Servers

Published on

spot_img

Cybersecurity Threats Evolved: Amatera Stealer Leveraging Ethereum Smart Contracts

In a world where digital threats are continually evolving, a newly identified campaign has revealed that hackers are increasingly manipulating decentralized infrastructure and legitimate development frameworks to escape detection. This particular campaign utilizes Ethereum smart contracts to hide command-and-control (C2) servers for a malware variant known as Amatera Stealer. The sophistication of this approach presents significant challenges for cybersecurity experts tasked with thwarting malicious attacks.

The distribution of this malware occurs through various channels that mimic legitimate operations. Hackers are relying on malicious websites and file-sharing platforms, prominently featuring services like Google Drive, MEGA, and Wormhole. These platforms intentionally spoof download portals to echo genuine distribution channels, making it increasingly challenging for users to discern the authenticity of the downloads they engage with.

The initial stage of the attack begins when victims unwittingly download a trojanized archive containing a Setup.exe file. Upon execution, users are greeted with a benign installation interface, while in the background, malicious processes engage silently, executing their harmful tasks without any visible signs of foul play. This silent infiltration strategy is particularly concerning, as it exploits unsuspecting users’ trust in familiar software installation methods.

The technique used in this malware campaign leverages the Ren’Py engine, a popular framework commonly used for developing visual novels and interactive fiction. By embedding malicious Python code within this trusted environment, attackers increase the plausibility of their payloads, making them even harder to detect. This tactic is part of a broader trend where trusted development ecosystems are weaponized to bypass established security controls, a phenomenon seen previously with frameworks like Bun and Deno.

Similar malicious campaigns have also been documented, specifically targeting other kinds of malware such as NwHStealer through Bun, as detailed in various cybersecurity blogs. These incidents highlight a disturbing trend: the abuse of legitimate frameworks and tools by cybercriminals to execute their attacks, which complicates traditional detection methods.

Once the RenPy Loader is activated, a complex multi-stage infection chain follows, characterized by obfuscated payload delivery and techniques aimed at evading defenses. Cybersecurity specialists from Malwarebytes have noted numerous ongoing campaigns distributing a malware loader known as RenPy Loader, also referred to as RenEngine Loader. This malware is often packaged with fake game downloads, cracked software, and mods, further misleading users.

The first stage of the loader is designed to extract encrypted components from embedded resources, including XOR-protected configuration files and ZIP archives. This level of sophistication continues with the implementation of sandbox detection checks and the removal of the ‘Mark-of-the-Web’ flag via alternate data streams, thereby bypassing critical Windows SmartScreen protections.

Following these evasive maneuvers, the loader executes a BAT script utilizing forfiles.exe, which launches a hidden instance of conhost.exe and invokes MSBuild.exe with a malicious project file known as Nancy.csproj. By employing this strategy, the malicious code executes inline .NET payloads through MSBuild property functions, a technique categorized as ‘living-off-the-land binary’ (LOLBIN) abuse. This method allows the malware to run legitimate Windows binaries in the execution of dangerous payloads.

Furthermore, the campaign features an exceptionally noteworthy tactic known as EtherHiding, which exploits blockchain technology to both store and retrieve details pertinent to malicious infrastructure. Instead of embedding C2 addresses directly in the malware, the loader utilizes an Ethereum JSON-RPC request to access a public blockchain endpoint. This query retrieves encrypted C2 information from a smart contract, significantly complicating detection and dismantling efforts, given that blockchain data is immutable and decentralized.

Upon retrieval of the C2 endpoint, the loader proceeds to download additional payloads. These payloads include a myriad of obfuscated .NET and native DLLs designed to deliver the final payload: the Amatera Stealer. This type of malware collection is engineered to harvest sensitive information from compromised systems. It targets browser-stored credentials, cryptocurrency wallet data, data from messaging applications, and local files. Such broad data extraction poses a significant risk, as stolen session tokens and credentials can facilitate account takeover attacks across multiple platforms.

The RenPy Loader’s adaptability has also been noted, as it has been observed delivering alternative payloads such as Lumma Stealer and HijackLoader. This flexibility is indicative of a broader trend toward a malware-as-a-service (MaaS) distribution model that is becoming increasingly common in cybercrime environments.

Moreover, the re-use of EtherHiding techniques across different campaigns, such as activities related to ClickFix, reinforces the notion that modern cybercriminals are continuously evolving their strategies. The combination of utilizing blockchain for C2 concealment, legitimate tool abuse, and intricate multi-stage execution underscores a significant paradigm shift in malware delivery, focusing on stealth and resilience.

As attackers creatively blend decentralized technologies with recognized software frameworks, traditional detection systems are facing mounting challenges in identifying and mitigating these complex threat vectors. The urgency for stronger, more adaptive cybersecurity measures has never been clearer, as attackers leverage sophisticated tactics to carry out their objectives unnoticed.

Source link

Latest articles

Japan Makes Significant Investments in AI-Powered Robots

Japan's Ambitious Bet on Physical AI: A Strategic Shift in Industrial Manufacturing In an increasingly...

FBI Issues Warning About Deepfake Videos Impersonating IC3 Leadership

The FBI has issued a warning regarding a significant escalation in a long-standing scam...

Behavioral Biometrics and the Detection of Nonhuman Threat Actors

As Anthropic's Mythos model illustrates, artificial intelligence (AI) is revolutionizing the field of cybersecurity....

CISA Report on US Election Cybersecurity Receives Praise

Apolitical Analysis Suggests Improved Patching Practices for Election Security In a political atmosphere rife with...

More like this

Japan Makes Significant Investments in AI-Powered Robots

Japan's Ambitious Bet on Physical AI: A Strategic Shift in Industrial Manufacturing In an increasingly...

FBI Issues Warning About Deepfake Videos Impersonating IC3 Leadership

The FBI has issued a warning regarding a significant escalation in a long-standing scam...

Behavioral Biometrics and the Detection of Nonhuman Threat Actors

As Anthropic's Mythos model illustrates, artificial intelligence (AI) is revolutionizing the field of cybersecurity....