This new phishing attack uses a sneaky infostealer to cause maximum damage

By Jurassic JennAug 16, 2024 14:09 PMTech
Share:
Phishing attack. Source: https://www.techradar.com/

Security researchers have identified a sophisticated new phishing campaign deploying an unusually comprehensive infostealer designed to exfiltrate a vast array of sensitive data, demonstrating significant advancements in malware capabilities.

Phishing Attack Mechanics

In its advisory, Barracuda Networks details how the attack initiates with a deceptive phishing email claiming to be a purchase order. These emails, sent from a fraudulent account ('yunkun[@]saadelbin[.]com'), lead victims to an attached ISO file, masquerading as legitimate content. Once interacted with, this file extracts an HTA (HTML application) that operates outside browser security restrictions, executing on the desktop.

This HTA file downloads an obfuscated JavaScript, which in turn triggers a PowerShell script. The script's function is to retrieve a ZIP file from a remote server, containing the final payload: a Python-based infostealer.

Phishing attack
Phishing attack

Infostealer Functionality and Data Collection

The infostealer malware is uniquely notable for its extensive data-stealing capabilities. Beyond common targets such as saved passwords, session cookies, and browsing histories, it aggressively harvests credit card information and cryptocurrency data from browser extensions like MetaMask and Coinbase Wallet. Additionally, it embarks on collecting PDF files from directories like Desktop, Downloads, and Documents by accessing special %AppData% folders.

Once operational, the malware quickly relays the stolen data to multiple email addresses at ‘maternamedical.top’, organized per data type (e.g., cookies, PDF files). Post completion, it self-deletes to evade detection.

Cybersecurity Implications

According to Barracuda, this attack represents a new level in data exfiltration threats. "The sheer volume and sensitivity of the extracted information, from browser data to financial details, presents substantial risks," states Saravanan Mohan, Barracuda's threat analyst manager. Such extensive data harvesting can facilitate further malicious activities such as organizational lateral movement and financial fraud.

In light of these evolving threats, it is crucial for organizations to enforce stringent security measures, including robust cybersecurity protocols, continuous threat monitoring, and educating employees about potential phishing tactics. Additionally, deploying AI and machine learning-based email protection systems can effectively detect and prevent these phishing attempts before they infiltrate user inboxes.

Earlier, SSP wrote that X faced Austrian complaint over AI training practices.

Top Articles

Symbolism and meaning of the magpie as spirit animal

Sep 18, 2024 17:03 PM

Symbolism of the cockroach and spiritual meanings of the totem animal encounter

Sep 18, 2024 15:24 PM

The meaning of the name Ava and its spiritual meanings

Sep 13, 2024 16:15 PM

Symbolism and power of the mockingbird totem animal: your spiritual encounter

Sep 13, 2024 12:16 PM
More News

Upcoming Travels for the Zodiac Signs

Sep 19, 2024 18:25 PM

5 Best Biopic Movies Of All Time

Sep 19, 2024 18:03 PM

Three zodiac signs to feel particularly motivated for academic pursuits in the next few weeks

Sep 19, 2024 17:44 PM

Ukrainian Marta Kostyuk Beats Briton Heather Watson at Korea Open

Sep 19, 2024 17:02 PM

British Superstitions: What's Commonly Believed

Sep 19, 2024 16:38 PM

How to Choose a Healthy Mayonaise

Sep 19, 2024 16:17 PM

The Starry Night Is Alive With Real-World Physics

Sep 19, 2024 15:56 PM

Respect for the Aged Day: Honoring the World's Oldest Living Person

Sep 19, 2024 15:34 PM

Sam Asghari Defends Ex-Wife Britney Spears After Influencer Mocks Singer's VMAs Reaction to Sabrina Carpenter

Sep 19, 2024 15:12 PM

Intel Embarks on Restructuring Journey as it Signs Multi-Billion-Dollar Deal with Amazon

Sep 19, 2024 14:54 PM

How to Make Homemade Coconut Yogurt

Sep 19, 2024 14:29 PM

Artistic Flourishing Among Three Zodiac Signs

Sep 19, 2024 14:08 PM

5 Best Sword and Sorcery Movies Of All Time

Sep 19, 2024 13:47 PM

Endrick Felipe Becomes Real Madrid's Youngest Scorer

Sep 19, 2024 13:27 PM

A Wobble from Mars: A Possible Indicator of Dark Matter

Sep 19, 2024 13:04 PM

Three zodiac sings will showcase innovative thinking next week

Sep 19, 2024 12:44 PM

The 5 Best Courtroom Dramas, Ranked

Sep 19, 2024 12:21 PM

Logitech Presents a Number of New Products

Sep 19, 2024 12:07 PM

Moderate Coffee and Caffeine Consumption Linked to Lower Cardiometabolic Disease Risk

Sep 19, 2024 11:38 AM

Lottery Club Turns Spare Change into $1 Million Prize

Sep 19, 2024 11:17 AM

Three zodiac signs are encouraged to embrace their adventurous spirits: horoscope for September 19

Sep 19, 2024 10:56 AM

Sean "Diddy" Combs' Legal Troubles and Personal Struggles Highlighted in Court

Sep 19, 2024 10:34 AM

Three zodiac signs to reach deeper communication level with others this weekend

Sep 19, 2024 10:15 AM

Three zodiac signs should offer support to their friends: horoscope for September 19

Sep 19, 2024 09:51 AM

Which Zodiac Signs Are Set for Life-Altering Encounters?

Sep 19, 2024 09:32 AM

Only a Few Will Find 5 Hidden Lemons in This Picture

Sep 19, 2024 08:49 AM