{"id":4280,"date":"2024-07-01T16:43:48","date_gmt":"2024-07-01T21:43:48","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/multi-malware-cluster-bomb-campaign-cyber-havoc"},"modified":"2024-07-01T16:43:48","modified_gmt":"2024-07-01T21:43:48","slug":"multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/01\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc\/","title":{"rendered":"Multi-Malware &#8216;Cluster Bomb&#8217; Campaign Drops Widespread Cyber Havoc"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt1576cc636e4f8e22\/668325333e9e353b53119918\/hemlock%281800%29_Alfio_Scisetti_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A financially motivated East European threat actor dubbed &#8220;Unfurling Hemlock&#8221; is using the cyber equivalent of a cluster bomb to drop up to 10 unique malware files at the same time on systems belonging to individuals in the US, Germany, Russia and multiple other countries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacker&#8217;s approach essentially involves using compressed Microsoft Cabinet (CAB) files nested within other compressed CAB files \u2014 sometimes as many as seven \u2014 to distribute a variety of information stealers and malware loaders on victim systems.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Widespread Cluster Bomb Malware Distribution\">Widespread Cluster Bomb Malware Distribution<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since at least February 2023, the adversary has distributed hundreds of thousands of malware files this way on systems belonging to some 50,000 users worldwide, according to researchers at OutPost24. The malware used includes information stealers such as Mystic Stealer, Rise Pro, and Redline; and loaders such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/attackers-combining-smoke-loader-propagate-in-new-campaign\" rel=\"noopener\">SmokeLoader and Amadey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">KrakenLabs&#8217; analysis suggested that Unfurling Hemlock is distributing at least some of the malware and loaders on behalf of other threat groups, while at the same time, it is also using other groups to help distribute its own cluster bombs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Based on malware samples uploaded to VirusTotal, more than half (50.8%) of the systems that the adversary has infected so far appear to be US based. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We named the actor &#8216;Unfurling Hemlock&#8217; because the samples distributed by them act as some sort of malware &#8216;cluster bomb.&#8217; where a single sample unfurls to spread several malware samples when infecting its victims,&#8221; Outpost24 threat researcher Hector Garcia <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/outpost24.com\/blog\/unfurling-hemlock-cluster-bomb-campaign\/\" rel=\"noopener\">wrote in a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;This appears to be a very thorough attempt to cover all bases and maximize benefit.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Outpost 24 uncovered the campaign when investigating reports by other researchers \u2014 including those at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/deconstructing-amadeys-latest-multi-stage-attack-and-malware-distribution\/\" rel=\"noopener\">McAfee<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 on attacks last year where threat actors deployed numerous malware samples at once on compromised systems. The security vendor&#8217;s analysis showed multiple similarities between the different attacks that allowed it to conclude a single actor was behind all of them. The company concluded the threat group is likely based in Eastern Europe based on the use of the Russian language in some malware samples, and its use of infrastructure based in the region to host and distribute the malware.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Carpet Bombing for Maximum Cyber Damage\">Carpet Bombing for Maximum Cyber Damage<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In its report, Outpost24 described Unfurling Hemlock as distributing its cluster bomb malware via email, and sometimes through malware loaders belonging to other threat groups. Attacks typically start with the execution of &#8220;weextract.exe,&#8221; which is a legitimate Windows executable for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/msi\/cabinet-files\" rel=\"noopener\">extracting cabinet files<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Cab files allow developers to compress and to package multiple files for distribution or for storage purposes. Cab files are often used as part of software installation packages and driver updates.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This executable contains nested compressed cabinet files, each level holding a malware sample and another compressed file,&#8221; Garcia wrote. &#8220;As each stage is unpacked, a new malware variant is dropped onto the victim&#8217;s machine. The final stage&#8217;s extracted files are executed in reverse order, with the most recently extracted malware executed first.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among the several files the threat actor has been deploying are obfuscators and tools for disabling Windows Defender and other <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/novel-edr-killing-ghostengine-malware-stealth\" rel=\"noopener\">endpoint threat detection and response (EDR) <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">systems on the victim machine.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When all of this is put together, we have a situation where the actor has a chance, with a single initial file, to steal the information from the victim, load further malware into the victim&#8217;s machine, and get paid for the infection using the malware of another group, all at the same time or any combination of the above,&#8221; Garcia said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Evan Dornbush, former NSA cybersecurity expert and co-founder of<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\"> <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Point3 Security, says the attacker&#8217;s tactic of packaging multiple known tools together and deploying them through nested cab files can be challenging for defenders to handle. The approach not only facilitates defense evasion, it also makes malware eradication harder to achieve and to confirm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Unfurling Hemlock harkens back to techniques reported in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/flame-malware-s-ties-to-stuxnet-duqu-details-emerge\" rel=\"noopener\">Flame<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/gauss-espionage-malware-7-key-facts\" rel=\"noopener\">Gauss<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (multi-staged malware and diversified payloads),&#8221; he notes. &#8220;This can make it particularly challenging for a victim to confirm complete eradication of infection as some of the second stage tools may have their own independent command-and-control systems (C2).&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Outpost24 expects other threat actors will start using the same \u2014 or similar tactics \u2014 as Unfurling Hemlock to distribute malware in the future. The key for defenders is to continue paying attention to the security basics.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;At the end of the day, these cluster bombs are not very complex, nor show a high degree of sophistication regarding obfuscation and anti-analysis techniques, and most of the malware dropped and executed in victim&#8217;s machines are very widely known and documented,&#8221; Garcia said.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/multi-malware-cluster-bomb-campaign-cyber-havoc\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A financially motivated East European threat actor dubbed &#8220;Unfurling Hemlock&#8221;<\/p>\n","protected":false},"author":12,"featured_media":4281,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4280","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=2560%2C1453&ssl=1",2560,1453,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=640%2C363&ssl=1",640,363,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=640%2C363&ssl=1",640,363,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=1536%2C872&ssl=1",1536,872,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=2048%2C1162&ssl=1",2048,1162,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=1024%2C581&ssl=1",1024,581,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/multi-malware-cluster-bomb-campaign-drops-widespread-cyber-havoc-scaled.jpg?fit=2560%2C1453&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4280","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4280"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4280\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4281"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}