← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Hijacked: How Cybercriminals Are Turning Anti-Virus Software Against You
LevelBlue Labs has recently observed a malicious campaign abusing legitimate anti-virus products to remain undetected. Upon achieving execution, the threat actor deploys several executables to gain a foothold in the infected system. One of these executables caught our attention as it masqueraded as different anti-virus components, while in reality they offer a proxy service through a Command and Control (C&C) server. The binaries are based on the legitimate anti-virus components but are modified to include the malicious code. This activity seems to be a continuation of the activity already reported by Sophos in late April and marks a new iteration in the toolset of this threat actor. In this new iteration of the campaign, we have observed Malwarebytes, BitDefender and APEX products being targeted amongst others.
Indicators of Compromise (10 / 17 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 1ade6a15ebcbe8cb9bda1e232d7e4111b808fd4128e0d5db15bfafafc3ec7b8e | — | 2024-07-25 | |
| FileHash-SHA256 | 7d96ec8b72015515c4e0b5a1ae6c799801cf7b86861ade0298a372c7ced5fd93 | — | 2024-07-25 | |
| FileHash-SHA256 | 949faad2c2401eb854b9c32a6bb6e514ad075e5cbe96154c172f5f6628af43ed | — | 2024-07-25 | |
| FileHash-SHA256 | 9c1e0c8c5b9b9fe9d0aa533fb7d9d1b57db98fd70c4f66a26a3ed9e06ac132a7 | — | 2024-07-25 | |
| FileHash-SHA256 | 9dc809b2e5fbf38fa01530609ca7b608e2e61bd713145f84cf22c68809aec372 | — | 2024-07-25 | |
| FileHash-SHA256 | ab1f101f6cd7c0cffc65df720b92bc8272f82a1e13f207dff21caaff7675029f | — | 2024-07-25 | |
| FileHash-SHA256 | b92cf617a952f0dd2c011d30d8532d895c0cfbfd9556f7595f5b220e99d14d64 | — | 2024-07-25 | |
| FileHash-SHA256 | baa50dbdb108e1769c5b0beff7462ea7deb8fd37782a49f0911619bc51d42105 | — | 2024-07-25 | |
| FileHash-SHA256 | bdd4174514eb882d56ddfc707b56123e987ea0e19354175bd47385d9e65db86f | — | 2024-07-25 | |
| FileHash-SHA256 | fb4fa180a0eee68c06c85e1e755f423a64aa92a3ec6cf76912606ac253973506 | — | 2024-07-25 |