PULSE NAME
Exposing FakeBat loader: distribution methods and adversary infrastructure
WHITE Eugenfest AlienVault 2024-07-02 Modified: 2024-08-01
242
IOCs
HIGH VOLUME
During the first semester of 2024, FakeBat (aka EugenLoader, PaykLoader) was one of the most widespread loaders using the drive-by download technique. Researchers uncovered multiple FakeBat distribution campaigns leveraging malvertising, software impersonation, fake web browser updates, and social engineering schemes on social networks to trick users into downloading the malware. Analysts monitored the FakeBat C2 infrastructure and identified over 130 domain names associated with high confidence to the FakeBat C2 servers since August 2023. The report provides IoCs, YARA rules and tracking heuristics to monitor the FakeBat distribution and C2 infrastructures.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
FakeBat EugenLoader PaykLoader
Indicators of Compromise (3 / 242 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname YARA
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 3c0d1d30ad289a57a315988c747c172f5aabe26e 2024-07-02
FileHash-SHA1 5efb3af1460b6a2a5da2ae9b515f830fe1d54287 2024-07-02
FileHash-SHA1 e50b4378c32b2d876eb220cfa0307afae97359b7 2024-07-02