Marketers Targeted in Multi-Stage Malware Attack in Vietnam

Published:

spot_img

Cyble Research Discovers Sophisticated Multi-Stage Malware Attack Targeting Job Seekers and Digital Marketing Professionals

The Cyble Research and Intelligence Lab (CRIL) recently uncovered a sophisticated multi-stage malware attack orchestrated by a Vietnamese threat actor targeting job seekers and digital marketing professionals. The campaign utilizes Quasar RAT, providing attackers complete control over compromised systems.

The attack begins with spam emails containing phishing attachments, tempting recipients to open an archive file posing as a PDF document. Once the LNK file is executed, PowerShell commands download obfuscated scripts from external sources to bypass traditional detection methods.

The Vietnamese threat actor intensifies operations by disseminating Ducktail malware to digital marketing professionals and expanding its arsenal to include information stealers and remote access trojans. Leveraging Malware-as-a-Service (MaaS) frameworks, these cybercriminals create versatile and scalable campaigns.

This campaign, linked to a Vietnamese threat group, targets professionals in digital marketing, e-commerce, and performance marketing sectors, with a special focus on Meta advertising. The malware employs virtual machine evasion techniques and advanced checks to avoid detection, including inspecting file names related to virtualization software and measuring time discrepancies in systems.

Upon successful execution, the malware checks for administrative privileges, escalates privileges if needed, and ensures persistence by modifying the Windows registry. Defense evasion strategies are employed to disable event tracing and encrypt sensitive data, while the deployment of Quasar RAT allows for data theft and remote control with reduced detectability. This advanced malware campaign highlights the evolving tactics and anonymity of cyber threat actors.

spot_img

Related articles

Recent articles

Walmart Shoppers Beware: Major Scam Hits Millions

A large-scale robocall scam is targeting millions of Walmart shoppers in the U.S. by impersonating the retailer’s customer service and inventing fake high-value purchases...

GCCA Celebrates Supreme Council’s Decision to Create GCC Civil Aviation Authority

GCC Civil Aviation Authority: A New Era for Gulf Air Travel A Significant Development for the Gulf Region The General Civil Aviation Authority (GCAA) of the...

Researchers Find Over 30 Vulnerabilities in AI Coding Tools That Risk Data Theft and RCE Attacks

Unveiling the IDEsaster: Security Flaws in AI-Powered Coding Environments Overview of Recent Vulnerabilities A recent investigation has uncovered over 30 security vulnerabilities lurking within popular AI-powered...

XIXILI Transforms Plus-Size Lingerie in Malaysia

## A New Era for Plus Size Lingerie: Introducing XIXILI’s Collection ### Redefining Lingerie Shopping KUALA LUMPUR, MALAYSIA - In a bold move that reshapes the...