Site icon TechNewsBoy.com

Hackers hiding malware in Windows Event Logs

In what seems to be a world first, hackers have used a custom malware dropper to plant fileless malware in Windows event logs for the Key Management Services (KMS).

Cybersecurity researchers from Kaspersky first spotted the new technique after being tipped off by a customer with an infected endpoint. The entire campaign, the researchers are saying, is “very targeted”, and deploys a large set of tools, some of which are custom-built, and some of which are commercial.

According to Kaspersky’s Denis Legezo, this is the first time this technique has been spotted in the wild. As he explained, the malware dropper copies WerFault.exe, the OS’ real error handling file, into the C:WindowsTasks folder, and then adds an encrypted binary resource to Wer.dll (short for Windows Error Reporting) into the same location. That way, through DLL search order hijacking, malicious code can be loaded into the system.

SilentBreak

The loader’s purpose, Legezo says, is to look for specific lines in the event logs. If it doesn’t find them, it will write pieces of encrypted shellcode, which would later form the malware for the next stage of the attack. 

In other words, wer.dll serves as a loader, and without the shellcode in Windows event logs, can’t do much harm. 

The entire technique, and the way it’s been pulled off, is “impressive”, Legezo told the publication. “The actor behind the campaign is rather skilled by itself, or at least has a good set of quite profound commercial tools,” he said, hinting at an APT attacker.

Who the threat actor is, is anyone’s guess at the moment. According to the researchers, the campaign started in September 2021, and given that the campaign bears no similarities to any previous attacks recorded, it’s likely that we’re looking at a completely new player.

For the time being, the researchers are dubbing the attacker SilentBreak.

Via: BleepingComputer

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechNewsBoy.com is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – abuse@technewsboy.com. The content will be deleted within 24 hours.
Exit mobile version