PULSE NAME
Fake Browser Updates Lead to BOINC Volunteer Computing Software
WHITE SocGholish AlienVault 2024-07-22 Modified: 2024-08-21
11
IOCs
MEDIUM VOLUME
This report details a recent malware campaign involving the infamous SocGholish/FakeUpdates malware, which tricks users into downloading fake browser updates. However, instead of installing common remote access tools (RATs) as the final payload, some infections resulted in the installation of the legitimate but maliciously misused BOINC (Berkeley Open Infrastructure for Network Computing) software, likely as a mechanism for gaining remote access and control over infected systems. The actors leveraged obfuscated PowerShell scripts and scheduled tasks for persistence, and connected to malicious BOINC servers hosted on domains like rosettahome.top and rosettahome.cn. While the threat actors' motivations are unclear, the illicit use of BOINC represents a novel technique for establishing command and control over compromised hosts.
Indicators of Compromise (11)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 01a8aeb0b350a1325c86c69722affd410ff886881a405743e1adb23538eff119 2024-07-22
FileHash-SHA256 380bd5f097b8501618cf8b312d68e97b3220c31172f82973fce3084157caa15e 2024-07-22
FileHash-SHA256 4716011ca9325480069bffeb2bbe0629fec6e5f69746f2e47f0a6894f2858c0b 2024-07-22
FileHash-SHA256 91e405e8a527023fb8696624e70498ae83660fe6757cef4871ce9bcc659264d3 2024-07-22
FileHash-SHA256 c5bfe4ddcf576b432f4e6ccce10dd3d219ee5f54497e0cc903671783924414a6 2024-07-22
domain ga1yo3wu78v48hh.top 2024-07-22
domain klmnnilmahlkcje.top 2024-07-22
domain rosetta.cn 2024-07-22
domain rosetta.top 2024-07-22
domain rosettahome.cn 2024-07-22
domain rzegzwre.top 2024-07-22