Swarez 木马和 Dropper 伪装成 15 热门游戏

In April of this year, 卡巴斯基实验室专家 recorded a large-scale campaign to distribute a Trojan and a dropper named Swarez.

The malware was distributed under the guise of 15 popular games, and attempts to download such files were recorded by the company’s products in 45 countries of the world.

The dropper was introduced through various sites that imitate platforms for illegal free software distribution. Many such sites distribute malware under the guise of keys for programs, including antivirus software, photo and video editors, as well as popular games.

Site page with hacked software
An example of a site page with hacked software for distributing 斯瓦雷斯.

The attackers used the following games as bait: Among US, Battlefield 4, Battlefield V, Control, Counter-Strike Global Offensive, FIFA 21, Fortnite, Grand Theft Auto V, 我的世界, NBA 2K21, Need for Speed Heat, PLAYERUNKNOWN’S BATTLEGROUNDS, Rust, The Sims 4, Titanfall 2. Multiple tags were used for each post to make landing pages appear at the top of search results.

Search results

The dropper was distributed in a ZIP archive, which contained another password-protected ZIP file and a text file containing this password. The launch of the malware resulted in the decryption and activation of the Taurus stealer Trojan.

从而, at the first stage of infection, the Swarez dropper executes an obfuscated CMD script that decrypts the legitimate AutoIt interpreter. Using it, the malware executes the AutoIt script, which is also obfuscated. Several checks are made to ensure that the file is not being executed in an emulated environment, and then the payload is decrypted using the RC4 algorithm. The resulting file is embedded in one of the system processes and executed in its context. This is Taurus, a paid stealer Trojan developed by the Predator 黑客组, with many features and customization options. It can steal cookies, saved passwords and autofill data from browsers, secrets for accessing cryptocurrency wallets, collect system information, text files from the user’s desktop, and even take screenshots. The Trojan sends all this information to the C&C服务器.

Users around the world are actively downloading software from dubious sources, and the authors of the Swarez dropper used this to their advantage. Attackers are constantly complicating their techniques and making every effort so that the user does not suspect that he is installing malware while downloading the program. That is why we recommend downloading the software only from the official websites of the developers.评论 Anton Ivanov, cybersecurity expert at 卡巴斯基实验室.

Let me remind you that I also recently wrote that TrickBot 获得了一个用于监控受害者的新模块.

赫尔加·史密斯

我一直对计算机科学感兴趣, 特别是数据安全和主题, 现在被称为 "数据科学", 从我十几岁起. 在加入病毒清除团队担任主编之前, 我曾在多家公司担任网络安全专家, 包括亚马逊的一名承包商. 另一种体验: 我在雅顿大学和雷丁大学任教.

发表评论

本网站使用的Akismet,以减少垃圾邮件. 了解您的意见如何处理数据.

返回顶部按钮