PULSE NAME
Hijacked: How Cybercriminals Are Turning Anti-Virus Software Against You
WHITE AlienVault 2024-07-25 Modified: 2024-08-24
17
IOCs
MEDIUM VOLUME
LevelBlue Labs has recently observed a malicious campaign abusing legitimate anti-virus products to remain undetected. Upon achieving execution, the threat actor deploys several executables to gain a foothold in the infected system. One of these executables caught our attention as it masqueraded as different anti-virus components, while in reality they offer a proxy service through a Command and Control (C&C) server. The binaries are based on the legitimate anti-virus components but are modified to include the malicious code. This activity seems to be a continuation of the activity already reported by Sophos in late April and marks a new iteration in the toolset of this threat actor. In this new iteration of the campaign, we have observed Malwarebytes, BitDefender and APEX products being targeted amongst others.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SbaProxy
Indicators of Compromise (3 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a57b8e9bea6144115796bfb723f3410c MD5 of fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 2024-07-25
FileHash-MD5 b6680e15c4f36e7b75fc6676bc911667 MD5 of baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 2024-07-25
FileHash-MD5 c73a9395d5eca18fd86700b086455c59 MD5 of bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f 2024-07-25