CryptBot Info-stealer Malware Being Distributed in Different Forms

CryptBot is an info-stealer malware distributed through malicious sites disguised as utility program downloading pages. When searching keywords such as names of certain programs, cracks, and serial numbers, the related distribution sites are exposed at the top of the search results page. Upon connecting to the page and clicking the download button, the user is redirected to the CryptBot malware downloading page. Numerous malicious sites were created using various keywords. When searching the most popular software keywords, many malicious sites…

njRAT Being Distributed through Webhards and Torrents

njRAT is a RAT malware that can perform various malicious activities after receiving commands from the attacker. Because it provides various features such as file downloading, command execution, keylogging, and user account information extortion, it has been steadily used by attackers since the past. Also, since one can easily find builders on the Internet, the malware is distributed in various forms to target domestic users. The most typical method is using torrents and webhards to distribute it under a disguise…

Phishing Site Targeting Domestic E-mail Service Users (Part 2)

The ASEC analysis team has been sharing information about various phishing e-mails in the ASEC blog. This time, the team aims to inform users about another discovered phishing site that targets domestic e-mail service users to distribute malware. The recently confirmed phishing site targets Naver Mail (mail.naver), Daum Mail (mail2.daum), and hiworks users to collect their information such as IDs, passwords, and user IPs. It then sends the information to the attacker’s e-mail. The top-level domain hxxp://za***if***i**pl*ce[.]com/ takes the form…

ASEC Weekly Malware Statistics (June 7th, 2021 – June 13th, 2021)

The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 7th, 2021 (Monday) to June 13th, 2021 (Sunday). For the main category, info-stealer ranked top with 67.7%, followed by RAT (Remote Administration Tool) malware with 20.3%, banking malware with 8.8%, and downloader with 2.2%. Ransomware did not make it to the main category due to a reduction in the number of cases….

Caution! Malicious Excel Macros Being Distributed Indiscriminately Through Emails!

The ASEC analysis team discovered that excel files containing the same type of malicious macros are being distributed indiscriminately through emails. Such excel files contain macros that additionally download malware. Recently, it was found that reply mails targeting random people were added with threatening text and malicious excel macro files. One feature that the three collected emails share is that they all disguise themselves as reply mails and distribute malicious macro excel files. In the example of Figure 3, the…