Marketers Targeted in Multi-Stage Malware Attack in Vietnam

Published:

spot_img

Cyble Research Discovers Sophisticated Multi-Stage Malware Attack Targeting Job Seekers and Digital Marketing Professionals

The Cyble Research and Intelligence Lab (CRIL) recently uncovered a sophisticated multi-stage malware attack orchestrated by a Vietnamese threat actor targeting job seekers and digital marketing professionals. The campaign utilizes Quasar RAT, providing attackers complete control over compromised systems.

The attack begins with spam emails containing phishing attachments, tempting recipients to open an archive file posing as a PDF document. Once the LNK file is executed, PowerShell commands download obfuscated scripts from external sources to bypass traditional detection methods.

The Vietnamese threat actor intensifies operations by disseminating Ducktail malware to digital marketing professionals and expanding its arsenal to include information stealers and remote access trojans. Leveraging Malware-as-a-Service (MaaS) frameworks, these cybercriminals create versatile and scalable campaigns.

This campaign, linked to a Vietnamese threat group, targets professionals in digital marketing, e-commerce, and performance marketing sectors, with a special focus on Meta advertising. The malware employs virtual machine evasion techniques and advanced checks to avoid detection, including inspecting file names related to virtualization software and measuring time discrepancies in systems.

Upon successful execution, the malware checks for administrative privileges, escalates privileges if needed, and ensures persistence by modifying the Windows registry. Defense evasion strategies are employed to disable event tracing and encrypt sensitive data, while the deployment of Quasar RAT allows for data theft and remote control with reduced detectability. This advanced malware campaign highlights the evolving tactics and anonymity of cyber threat actors.

spot_img

Related articles

Recent articles

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...