Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Ande Loader malware targets North American manufacturing industry
    Cyber Security

    Ande Loader malware targets North American manufacturing industry

    techempireBy techempireNo Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 14, 2024Editorial DepartmentInternet Threats/Malware

    Malware loader

    A threat actor named Blind Eagle was observed using loader malware called Ande Loader to spread remote access Trojans (RATs) such as Remcos RAT and NjRAT.

    eSentire said the attacks took the form of phishing emails targeting Spanish-speaking users in the North American manufacturing industry.

    Blind Eagle (also known as APT-C-36) is a financially motivated threat actor that has orchestrated cyberattacks against entities in Colombia and Ecuador to deliver various RATs, including AsyncRAT, BitRAT, Lime RAT, NjRAT , Remcos RAT, and Quasar RAT.

    Internet security

    The latest findings mark an expansion of the threat actor’s target footprint, also leveraging phishing with RAR and BZ2 archives to activate infection chains.

    The password-protected RAR archive is accompanied by a malicious Visual Basic Script (VBScript) file, which is responsible for establishing persistence in the Windows startup folder and launching the Ande Loader, which in turn loads the Remcos RAT payload.

    In another attack sequence observed by a Canadian cybersecurity firm, BZ2 files containing VBScript files were distributed via Discord content delivery network (CDN) links. In this case, the Ande Loader malware deletes NjRAT instead of Remcos RAT.

    “Blind Eagle threat actors have been using ciphers written by Roda and Pjoao1578,” eSentire said. “One of the ciphers developed by Roda has a hardcoded server, an injector component that hosts the cipher, and a cipher used in the Blind Eagle campaign. Other malware.”

    Internet security

    This development comes as SonicWall reveals the inner workings of another loader malware family called DBatLoader, detailing its use of a legitimate but vulnerable driver related to the RogueKiller AntiMalware software (truesight.sys). Terminate security software as part of Bring Your Your Own. Own Vulnerability Driver (BYOVD) attack and ultimately deliver Remcos RAT.

    “The malware was received as an email attachment in a file and was highly obfuscated and contained multiple layers of encrypted material,” the company said earlier this month.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.