Malware
XWorm
Malware with wide range of capabilities ranging from RAT to ransomware.
Indicators of Compromise 31
Domain api[.]telegram[.]org Domain cdnjsdelivr[.]beer Domain dontpad[.]com Domain download[.]sftp-api-group-wechat[.]com Domain gulf[.]moneroocean[.]stream Domain sekirolegion[.]duckdns[.]org Domain test-steve[.]cyou Domain update-launcher[.]xyz Domain update[.]constant-path[.]xyz Filename DotNetZip.dll Filename GoFlyDrv.sys Filename PythonLauncher-*.lnk Filename STAAAAAS.exe Filename WmiPrvSE.exe Filename Wmi_Framework_APIKEY_wmsnet_<random_value>.lnk Filename ZrvEsJQzWQ.exe Filename dpapimig.exe Filename putty Filename putty.exe Filename wmiframework.exe GitHub Repo Mash3Do GitHub Repo lencod SHA-256 1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505 SHA-256 4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f SHA-256 5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898 SHA-256 81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f SHA-256 ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2 SHA-256 f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27 IP 193[.]221[.]200[.]219 Registry User Mash3Do Registry User lencod
MITRE ATT&CK TTPs 29
T1006 T1012 T1014 T1021.001 T1021.002 T1027 T1053.005 T1055 T1055.001 T1055.015 T1059.001 T1068 T1070.004 T1070.009 T1071.001 T1071.004 T1078 T1082 T1083 T1090 T1090.004 T1105 T1110.003 T1204.002 T1482 T1496 T1548.002 T1557 T1566
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
Dynamic-link Library Injection
Defense Evasion
ListPlanting
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Clear Persistence
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Domain Fronting
Command And Control
Ingress Tool Transfer
Command And Control
Password Spraying
Credential Access
Malicious File
Execution
Domain Trust Discovery
Discovery
Resource Hijacking
Impact
Bypass User Account Control
Privilege Escalation
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Source Articles
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Aeternum is a recently discovered C++ botnet loader that uses the Polygon blockchain for decentralized command-and-control (C2) operations. The malware retrieves encrypted or plaintext instructions from smart contracts on the blockchain by querying public RPC endpoints, enabling resilient and low-cost infrastructure resistant to takedowns. Three distinct malware samples were analyzed: the initial Aeternum loader, a Python-based downloader, and a multi-component payload combining XWorm RAT, XMRig cryptocurrency miner, and data exfiltration tools. The threat leverages Telegram APIs and GitHub repositories for secondary C2 and payload delivery, while using weak encryption schemes that allow decryption via contract address and payload analysis.
unit42 ·4w ago
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet, a financially motivated threat actor active since 2023 and previously tracked as UNC5669, has targeted Brazilian financial, retail, and e-commerce organizations to conduct fraudulent transactions via payment systems like Pix, STR, and Boleto. The group gains initial access through password spraying, social engineering via WhatsApp, and exploitation of vulnerable JBoss AS servers to deploy web shells. They use a suite of custom backdoors such as LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, along with tools like COBALTSPIN for lateral movement and SOCKS5 tunneling, to maintain persistence and execute hundreds of fraudulent transactions. The actor leverages compromised government websites for C2 infrastructure, disables Windows Defender via PowerShell, and uses LLMs to accelerate malware development, indicating a shift toward more sophisticated, infrastructure-level financial attacks.
hacker-news ·1w ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago