More advanced obfuscation techniques have been adopted by a new Hijack Loader malware variant, the SHELBY malware, and the Emmenhtal Loader to facilitate clandestine compromise, according to The Hacker News.
After being spread via code-signing certificates and the ClickFix attack technique, Hijack Loader was discovered by Zscaler ThreatLabs to have been updated to include call stack spoofing for API origin and system call concealment which was previously observed in the CoffeeLoader malware as well as a pair of new modules allowing virtual machine identification and persistence. Another report from Elastic Security Labs detailed the novel SHELBY malware family, which is being deployed via phishing emails with a ZIP archive attachment executing the SHELBYLOADER DLL loader that uses GitHub as a command-and-control server for stealth. On the other hand, Emmenhtal Loader, also known as PEAKLIGHT, was observed by GDATA researchers to have exploited 7-Zip files to stealthily launch the SmokeLoader malware, which also had its concealment improved through the commercial .NET protection tool .NET Reactor.
A Russian national has been charged by the U.S. Department of Justice for allegedly operating approximately 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to around 80,000 users in 2016 and 2017.
The malicious code performs two main functions: a mobile ad-fraud and gambling-redirect chain, and a WebKit-to-kernel exploit chain on iPhones that installs spyware.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news