CyberSecurity SEE

Post-DEF CON Phishing Campaign Distributes AMOS and NetSupport Malware

Post-DEF CON Phishing Campaign Distributes AMOS and NetSupport Malware

A recent phishing campaign has sparked concerns among security experts, particularly as it targeted attendees of the renowned Black Hat and DEF CON conferences. The campaign involved the distribution of information-stealing malware and remote access tools through deceptive means, including a malicious Google Doc and counterfeit DocSend installers for both macOS and Windows operating systems.

According to insights gathered by the Huntress team, they became aware of the phishing activities after one of their researchers received a direct message on X, previously known as Twitter, on August 9. The message originated from an account impersonating the vice president and marketing head of CoinDesk. The purported intention behind the message was to inquire about the researcher’s plans for attending upcoming conferences. While the researcher recognized this interaction as a scam, they strategically engaged further to ascertain the goals of the attacker.

Subsequent investigations revealed that this same fraudulent account had been reaching out to numerous conference participants with similar inquiries, and was posting content designed to lend credibility to its operation. This organized approach highlights a troubling trend where cybercriminals capitalize on networking opportunities at significant events like Black Hat and DEF CON.

The attacks escalated when the threat actor sent a Google Doc ostensibly serving as a planning document for the conference. This document appeared to be partially encrypted and required an access key for full functionality—an access key that was promptly provided by the attacker through private messaging. Interestingly, the key failed to function as intended. This failure was, in fact, a deliberate aspect of the scam. Instead of granting access to the document, the decryption failure led the victim to a set of instructions aimed at resolving the issue. However, this was merely a ruse to initiate the malware delivery process.

The malicious Google Doc included a custom sidebar created with a Google Apps Script, which referenced a file called DecryptPanel.html. Research conducted by Huntress revealed that this script executed several functions: it checked hard-coded keys, collected data from the victim’s computer, communicated activities via Telegram, and determined the appropriate payload based on whether the victim was operating macOS or Windows. Notably, researchers identified Russian-language comments embedded in the code, hinting at the campaign’s origins.

After encountering the access key issue, the malicious sidebar presented victims with two options: “Document Decryption” instructions or a “Manual Update” option, both created to facilitate malware installation. For macOS users, the first option instructed them to execute a command in Terminal, whereas the manual option redirected them to a GitHub Releases page, delivering a file named GAPIUpdate.dmg. The accompanying instructions cleverly guided users to bypass macOS Gatekeeper, a built-in security feature, ultimately compromising their systems.

Meanwhile, Windows users were misled in a different manner. They received the same failure notice before being informed that a “Google API Connector” required an update. In this case, the update was orchestrated through a ClickOnce deployment that was controlled by the attacker. Analysis revealed that the application carried a fraudulent certificate belonging to a Norwegian company, raising further flags regarding the legitimacy of the operation.

The campaign’s complexity did not end there. Huntress investigators noted that even after a failed malware delivery attempt, the attacker persisted. A follow-up attempt involved a document posing as a Dropbox DocSend share, tricking recipients into believing that a desktop version of DocSend was necessary for viewing. The subsequent download site was structured to vary installers based on the browser’s User-Agent, providing further evidence of the attacker’s calculated approach.

For macOS users, the follow-up file, named DocSendInstaller.zip, again employed the Atomic macOS Stealer (AMOS) infostealer variant. Windows users were directed to download a .exe file which, despite its legitimate appearance, harbored malicious elements. The installer presented a façade of a legitimate application while deploying malware in the background, collecting detailed system information to send back to the attacker’s infrastructure.

Huntress also uncovered additional layers of complexity within the malware’s design. One payload exploited a Windows process, enabling the attackers persistent remote access through a modified version of legitimate remote administration software. In turn, commands could be sent without signs of compromise visible to the user.

As investigations continued, it became clear that the ultimate goal involved targeting cryptocurrency wallets and credentials, an aspect underscored by the malware’s design and behavior. The presence of various payloads and command servers indicated that this was part of a broader operation far beyond the initial attacks.

In conclusion, cybersecurity experts have reiterated caution for individuals working within the tech community, particularly those attending major conferences. Engaging with new contacts during such events can inadvertently lead to vulnerabilities that cybercriminals are eager to exploit. The Huntress team advises that any systems potentially compromised during this campaign should be isolated, with relevant forensic evidence preserved. It’s critical for victims to treat all stored credentials as compromised and execute a thorough reset on all accounts, particularly those connected to digital currencies. The ongoing investigation into this multifaceted phishing scheme highlights the critical need for vigilance and awareness in an increasingly treacherous cyber landscape.

Source link

Exit mobile version