An undetermined threat actor was observed weaponizing a cluster of domains masquerading as legitimate IP scanner software sites to distribute malware via a previously unseen Windows backdoor.In a blog post April 17, Zscaler ThreatLabz said the threat actor registered multiple look-alike domains using a typosquatting technique and leveraged Google Ads to push these fraudulent domains to the top of search engine results targeting specific search keywords, thereby luring potential victims to these IP scanner sites.The Zscaler researcher said the newly discovered backdoor uses several techniques such as multiple stages of Windows DLL sideloading, abusing the DNS protocol for communicating with the command-and-control (C2) server, and evading memory forensics security solutions.Zscaler dubbed this backdoor “MadMxShell” for its use of DNS MX queries for C2 communication and its very short interval between C2 requests.“The selection of spoofed software by this threat actor suggests that their targets primarily consist of IT professionals, particularly those in IT security and network administration roles,” wrote the researchers. “This aligns with the recent trend observed where advanced persistent threat groups such as Nobelium crafted attacks targeting these teams.”The MadMxShell campaign stands out as a particularly unique and dangerous Windows backdoor because of its multi-pronged approach, said Sarah Jones, cyber threat intelligence research analyst at Critical Start. Jones said unlike most backdoors that cast a wide net, MadMxShell targets a specific group: IT security and network administration teams.
Vulnerability Management, Malware
‘MadMxShell’ leverages Google Ads to deploy malware via Windows backdoor

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



