Red Cross-Themed Phishing Attacks Distributing DangerAds and AtlasAgent Backdoors

0
794

[ad_1]

Sep 27, 2023THNMalware / Cyber Attack

A brand new risk actor often known as AtlasCross has been noticed leveraging Red Cross-themed phishing lures to ship two beforehand undocumented backdoors named DangerAds and AtlasAgent.

NSFOCUS Security Labs described the adversary as having a “excessive technical stage and cautious assault angle,” including that “the phishing assault exercise captured this time is a part of the attacker’s focused strike on particular targets and is its primary means to attain in-domain penetration.”

The assault chains begin with a macro-laced Microsoft doc that purports to be a couple of blood donation drive from the American Red Cross that, when launched, runs the malicious macro to arrange persistence, exfiltrate system metadata to a distant server (knowledge.vectorse[.]com) that is a sub-domain of a official web site belonging to a structural and engineering agency primarily based within the U.S.

UPCOMING WEBINAR

Fight AI with AI — Battling Cyber Threats with Next-Gen AI Tools

Ready to sort out new AI-driven cybersecurity challenges? Join our insightful webinar with Zscaler to handle the rising risk of generative AI in cybersecurity.

Supercharge Your Skills

It additionally extracts a file named KB4495667.pkg (codenamed DangerAds), which, subsequently acts as a loader to launch shellcode that results in the deployment of AtlasAgent, a C++ malware able to gathering system info, shellcode operation, and operating instructions to acquire a reverse shell in addition to inject code right into a thread within the specified course of.

Both AtlasAgent and DangerAds incorporate evasive options to make it much less prone to be found by safety instruments.

AtlasCross is suspected to have breached public community hosts by exploiting recognized safety vulnerabilities and turning them into command-and-control (C2) servers. NSFOCUS mentioned it recognized 12 completely different compromised servers within the U.S.

The true id of AtlasCross and its backers at present stays a puzzle.

“At this present stage, AtlasCross has a comparatively restricted scope of exercise, primarily specializing in focused assaults towards particular hosts inside a community area,” the corporate mentioned. “However, the assault processes they make use of are extremely strong and mature.”

Found this text fascinating? Follow us on Twitter and LinkedIn to learn extra unique content material we submit.

LEAVE A REPLY

Please enter your comment!
Please enter your name here