New Malware Loader 'Verblecon' Infects Hacked PCs with Cryptocurrency Miners

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,151
An unidentified threat actor has been observed employing a "complex and powerful" malware loader with the ultimate objective of deploying cryptocurrency miners on compromised systems and potentially facilitating the theft of Discord tokens.

"The evidence found on victim networks appears to indicate that the goal of the attacker was to install cryptocurrency mining software on victim machines," researchers from the Symantec Threat Hunter Team, part of Broadcom Software, said in a report shared with The Hacker News.

"This would appear to be a relatively low-reward goal for the attacker given the level of effort that would have been required to develop this sophisticated malware."

This advanced piece of malware, dubbed Verblecon, is said to have been first spotted two months ago in January 2022, with the payload incorporating polymorphic qualities to evade signature-based detections by security software.

In addition, the loader carries out further anti-analysis checks to determine if it's currently being debugged or opened in a virtual or sandboxed environment, before proceeding to copy itself into the machine and connecting to a remote server to retrieve an encrypted blob that contains a URL, which is then used to fetch the miner payloads.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top