City
Epaper

Vietnam-based hackers target India, US & UK with potential malware: Report

By IANS | Updated: October 22, 2023 15:50 IST

New Delhi, Oct 22 Vietnam-based cybercrime groups are targeting digital marketing firms based in India, the US and ...

Open in App

New Delhi, Oct 22 Vietnam-based cybercrime groups are targeting digital marketing firms based in India, the US and the UK by hijacking Facebook business accounts in a malicious campaign, a new report has found.

According to the cybersecurity company WithSecure, the popular malware 'Darkgate' has been combined with a Malware as a Service (MaaS) toolkit to infect victims with rival remote access trojans (RATs) and additional information-stealing malware like Ducktail, Lobshot, and Redline.

Multiple infection attempts with DarkGate malware were identified by researchers, targeting these countries on August 4.

The lure documents, target patterns, themes, delivery methods, and overall attack tactics are similar to those seen in recent DuckTail infostealer campaigns, the report said.

DarkGate is a Remote Access Trojan (RAT) that first emerged in cyberspace in 2018. It is usually offered as a Malware-as-a-Service tool to cybercriminals.

The researchers examined open-source data associated with the DarkGate malware campaign and discovered connections to multiple infostealers. This pattern indicates that these attacks are being carried out by the same group or threat actor.

According to the report, the attack began with a file called 'Salary and new products.8.4.zip.' When unwitting users downloaded and extracted it, a VBS script was activated.

This script renamed and duplicated the original Windows binary (Curl.exe) to a new location before connecting to an external server to retrieve two additional files: autoit3.exe and an Autoit3 script compiled.

Following that, the script executed the executable, de-obfuscated, and assembled the DarkGate RAT with the help of strings from the script.

“Based on what we’ve observed, it is very likely that a single actor is behind several of the campaigns we’ve been tracking that target Meta Business accounts,” said senior threat intelligence analyst Stephen Robinson.

After gaining control of an account, the attackers can engage in a variety of malicious activities such as malware distribution and fraud, the report warned.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

InternationalEarthquake of magnitude 4.6 strikes Pakistan

Other SportsWomen’s World Cup: ‘Perfect Strike’ as Amit Shah, former players hail India’s big win over Pakistan

NationalNortheast Frontier Railway records 9.63 per cent rise in freight unloading

Other SportsPKL 12: Bengaluru Bulls earn revenge over Tamil Thalaivas, seal 33-29 win in thriller

Other SportsHosting World Para Athletics Championships successfully gives India pride of place globally, say top stars, legends

Technology Realted Stories

TechnologyBSNL’s indigenous 4G network to be upgraded to 5G in next 6-8 months: Minister

TechnologyPeople’s Plan Campaign paves the way for more responsive, empowered Panchayats

TechnologyIndia should focus on atmanirbhar innovation, aims to rank in top five AI nations globally: Scindia

TechnologyImpact of GST reforms starts showing as festive sales breaks 10-year record: Experts

TechnologyBitcoin touches record high crossing $125,000