Security News CloudFanta Malware Uses Popular Online Storage App to Infect Users

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
A new malware campaign dubbed CloudFanta is suspected to be behind the theft of 26,000 email credentials and also monitors online banking activities.

Netskope Threat Research Labs said that CloudFanta has been in operation since July 2016 and primarily targets Brazilian users. Unlike the grape or orange, horrible-for-you but oh-so-delicious soft drink that it shares its name with, CloudFanta arrives as much malware does: Via an attachment or a link in a spear-phishing email.

But from there, its modus operandi demonstrates the effective use of cloud services for hosting malware by malicious threat actors—it uses a popular online storage app to complete the infection cycle.

“We observed the CloudFanta malware using the SugarSync cloud storage app for delivering a JAR file that functions as a downloader…for DLL files,” Netskope said in an analysis. “[These] are responsible for stealing the victim’s email credentials, sending malicious emails on behalf of the victim and also for monitoring victims’ online banking activities.”

The DLL files are initially delivered with the .png extension, which, along with the use of SSL/HTTPS communication with SugarSync,s allow CloudFanta to stay under the radar of a number of traditional, network-based security solutions.

“The use of cloud services makes the delivery of malware very easy, effectively making it easier to compromise and gain access to users’ data,” Netskope said. “This clearly signifies an urgent need for enterprises to employ a multi-layered security approach with a strong focus on cloud services.”

Enterprises should track the usage of unsanctioned cloud services and enforce DLP policies to control files and data entering and leaving the corporate environment; and, they should create a security policy to block portable executable files with content type “image/png.”

Full Article. CloudFanta Malware Uses Popular Online Storage App to Infect Users
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top