Received Estimate/Purchase Order Email? Take Caution When Opening Them! Posted By AhnLab_en , February 22, 2021 With the start of 2021, malicious emails disguised as business emails are being discovered as numerous companies have started their business. Thus, users must remain vigilant when opening email. The discovered attacks used e-mails disguised as business-related content, such as ‘estimate request’ or ‘purchase orders,’ with malicious files attached. Upon running the attachment file, the user either gets directed to a phishing site that requires account information, or gets infected with info theft malware. In January and February this year, ASEC has discovered numerous cases of e-mails disguised as ‘estimate request’ or ‘purchase order’ to attempt to steal user’s info. The email was written in quite fluent Korean, and it had the phrase ‘Please check the attached file.’ written in…
Distribution of Malware Disguised as ‘2021 Ministry of National Defense Work Report Revised’ Posted By jcleebobgatenet , February 18, 2021 On January 24, ASEC discovered the distribution of malware disguised as ‘2021 Ministry of National Defense Work Report Revised.’ As shown below, the extension of the distributed malware is *.pif, but it is an executable file just like the EXE extension. Once run, a file that is identical to that of a PDF document file accessible on the website of Ministry of National Defense is shown to the user. However, it is designed to run malware (DLL format) along with…
BlueCrab Ransomware Installing Hacking Tool CobaltStrike in Corporate Environments Posted By jcleebobgatenet , February 5, 2021 The ASEC analysis team confirmed that during the BlueCrab ransomware (=Sodinokibi, REvil) infection process, which is distributed in JS form, the CobaltStrike hacking tool was distributed under certain conditions. CobaltStrike hacking tool is a limited tool used for mock hacking test purposes under legitimate purposes; however, it has been actively used in malware since the recent source code leak. Since recently confirmed BlueCrab ransomware distribution JS file checks the corporate Active Directory (AD) environment and installs the CobaltStrike hacking tool…
BlueCrab Ransomware’s Continuous Attempts to Bypass Detection Posted By jcleebobgatenet , February 3, 2021 BlueCrab Ransomware (=Sodinokibi Ransomware) is a ransomware that is being vigorously distributed to Korean users. It distributes through a fake forum web page created using various search keywords. The infection process begins at the moment when a user runs the JS file downloaded from the distribution page. The distribution page appears in the front pages of a search engine, allowing it to be easily accessible. Because of this, cases of infection are being continuously reported by users. ASEC analysis team…
Caution – Emails with the Title ‘Request for Purchase Order’ being Distributed to Companies Posted By jcleebobgatenet , January 28, 2021 Multiple malicious emails with the title ‘Request for Purchase Order’ are being distributed to multiple companies. These spam mail attacks, which were first distributed in the second half of last year to random companies with the purpose of stealing user account, are still being distributed. To steal a user’s company email account, the attacker either prompted the users to access a phishing web page, or distributed executable of Lokibot, the info-stealer malware. So far, two titles are found in the…