Malware

Novel ChaosBot backdoor examined

Attackers have compromised a financial services firm's environment with the newly emergent ChaosBot backdoor late last month, The Hacker News reports.

Exploitation of both a breached Active Directory account and Windows Management Instrumentation facilitated remote command execution and the eventual distribution and execution of the Rust-based ChaosBot malware, according to an eSentire analysis.

ChaosBot has also been spread through phishing emails with illicit Windows LNK files that execute a PowerShell command. Aside from receiving commands for PowerShell command execution, screenshot capturing, and file uploading or downloading from its Discord command-and-control server, ChaosBot was also discovered to evade virtual machines and Event Tracing for Windows.

Such findings come as the Chaos ransomware was reported by Fortinet FortiGuard Labs to have spawned a more potent C++-based variant dubbed "Chaos-C++," which opts to remove large files.

"This dual strategy of destructive encryption and covert financial theft underscores Chaos' transition into a more aggressive and multifaceted threat designed to maximize financial gain," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds