Malware News New GZipDe Malware Drops Metasploit Backdoor (infection is a multi-step process)

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Security researchers from AlienVault have discovered a new malware strain named GZipDe that appears to be part of a targeted attack —most likely a cyber-espionage campaign.

Researchers discovered this new malware earlier this week after a user from Afghanistan uploaded a boobytrapped Word document on VirusTotal.

The document contained text taken from an article published last month about the Shanghai Cooperation Organization Summit, a political conference on Eurasian political, economic, and security topics.

Malware most likely used for cyber-espionage

Because VirusTotal hides precise information about the source of the upload, the target of this attack is unknown.

"We’ve only seen one sample of the malware," Chris Doman, a security researcher with AlienVault told Bleeping Computer.

"It seems very targeted," Doman added. "Given the decoy document is in English and uploaded from Afghanistan, it may have been targeting someone in an embassy or similar there."

A GZipDe infection is a multi-step process

This Word file was just the first step in a multi-step infection process, which Doman detailed in a report published yesterday.

The document lured users into enabling macros, which then executed a Visual Basic script, which ran some PowerShell code, which downloaded a PE32 executable, which later dropped the actual malware —GZipDe.

... ... ....
... ....

According to Doman, GZipDe is coded in .NET, and uses "a custom encryption method to obfuscate process memory and evade antivirus detection."

GZipDe is a "downloader," meaning its role is to fetch another more potent threat from a remote server.

This second server was down when researcher found the malware, and under normal, the investigation would have been over at this phase. Fortunately, the AlienVault team got lucky because IoT search engine Shodan had indexed the server and "recorded it serving a Metasploit payload."
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top