Ransomware, Malware, Identity

Updated GlassWorm attack campaign uncovered

Privacy concept: pixelated words Malware on digital background, 3d render

Threat actors have used a multi-stage framework deploying a remote access trojan and a fake information-stealing Google Docs Offline extension for Chrome in yet another twist to the GlassWorm campaign, The Hacker News reports.

Attacks in the campaign, which avoided Russia-based systems, involved the exploitation of Solana transactions as a dead drop resolver for command-and-control server and OS-specific payload retrieval, according to an analysis from Aikido researchers.

Installation of an information-stealing framework with cryptocurrency wallet and credential theft and system profiling functionality as a second-stage payload enables exfiltration of obtained data in the form of a ZIP archive to an external server and the subsequent retrieval of a .NET binary for hardware wallet phishing and a Websocket-based JavaScript RAT for browser data compromise and arbitrary code execution. Targeted session surveillance is then made possible by the JavaScript RAT's forced installation of the malicious Chrome extension on Windows and macOS systems.

Such findings come as malicious npm packages spoofing the WaterCrawl Model Context Protocol server were reported by Koi researchers to have facilitated illicit payload delivery in GlassWorm attacks.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds