KRBanker Targets South Korea Through Adware and Exploit Kits
Unit 42 details KRBanker banking trojan targeting South Korean bank users via KaiXin exploit kit and NEWSPOT adware, using pharming and process hollowing.
KRBanker (aka Blackmoon) is a banking trojan targeting online banking users in the Republic of Korea, with roughly 2,000 unique samples and 200+ pharming servers observed by Unit 42 over six months. It is distributed through the KaiXin exploit kit exploiting Adobe Flash CVE-2014-0569 and CVE-2015-3133, and through the NEWSPOT adware update channel that also delivers the Venik trojan. The trojan uses process hollowing, retrieves pharming server IPs from Qzone profile nickname fields, and abuses Proxy Auto-Config with a local proxy to redirect banking traffic to forged sites.
The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Unit 42 uncovers the Fractured Block campaign using the CARROTBAT dropper to deliver SYSCON and OceanSalt malware in cryptocurrency-themed attacks across Southeast Asia.
Unit 42 identified 29 CARROTBAT dropper samples used in the Fractured Block campaign, delivering decoy documents on cryptocurrencies, exchanges, and Korean political topics. Early samples delivered the SYSCON RAT, which uses FTP for command and control, while later ones dropped the previously reported OceanSalt malware. CARROTBAT supports 11 decoy file formats and uses certutil to download and execute payloads. Initial discovery stemmed from a December 2017 spear phishing attack on a British government agency, with infrastructure overlap tying the campaign to KONNI activity.
Bisonal Malware Used in Attacks Against Russia and South Korea
Unit 42 details a Bisonal malware variant, active since 2014, targeting Russian and South Korean defense organizations via PDF-disguised spearphishing emails.
In early May, Unit 42 discovered a campaign delivering a Bisonal malware variant against at least one Russian communications security and cryptography company and one unidentified organization in South Korea. The variant, in the wild since at least 2014, introduces a new C2 cipher and rewritten networking and persistence code, with only 14 samples collected to date. Attackers spoofed Russian state corporation Rostec in spearphishing emails carrying an executable disguised with a PDF icon; the dropper decrypts an RC4-encrypted DLL and establishes persistence via a registry Run key. Bisonal has been used since 2013 against government, military, and defense targets in South Korea, Russia, Japan, and India, alongside successors Bioazih and Dexbia.
Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Unit 42 uncovered Eleethub, a Perl-based Bitcoin mining botnet using a crafted rootkit and libprocesshider to evade detection, still under development with few infections.
Unit 42 discovered an under-development Perl Shellbot campaign that mines Bitcoin using xmrig and emech while evading detection via a rootkit that replaces the ps tool and the LD_PRELOAD-based libprocesshider.so library. Infected devices download a malicious shell script, connect to IRC-based C2 at eleethub.com and the UnderNet network, and can receive commands for UDP/TCP floods, port scans, and HTTP attacks. The botnet can affect Unix systems and Windows 10 hosts running a Linux subsystem, and its operators use the 'Los Zetas' branding, though they are unlikely to be the Mexican drug cartel. Researchers found only a few compromised 'zombies' before the campaign expanded.
Nearly 800 Malicious npm Packages Deliver Cross
Nearly 800 typo-squatted npm packages deliver WEL1DROPPER, a cross-platform downloader installing RAT and infostealer payloads on Windows, macOS, Linux.
Researchers found roughly 800 npm packages with AI-generated typo-squat names that trigger a WEL1DROPPER downloader when loaded via require() rather than install hooks. The downloader fetches payloads from Cloudflare Workers hosts, falling back to DNS TXT records from wel1.ru, then achieves persistence, sandbox checks, ETW/AMSI patching and Sliver C2 deployment on Linux. Domains like tcsbank.ru suggest targeting of Russian financial institutions; Sonatype tracks the campaign as Flooding Dropper, a possible evolution of the Moika dependency-confusion campaign. Unit 42 separately documented npm/PyPI crypto stealers and malicious Chrome extensions that turn browsers into residential proxy crawlers.
Kimwolf botnet rebuilt to survive takedowns, researchers say
Palo Alto Unit 42 reports the Kimwolf/Aisuru botnet now uses HTTP/2 Chrome-impersonation floods and Ethereum blockchain-based command resolution to survive takedowns.
Palo Alto Networks' Unit 42 says a new Kimwolf/Aisuru botnet version active since February conducts DDoS floods over HTTP/2 with full Chrome browser fingerprints, making attack traffic hard to distinguish from real users. The malware resolves command servers via the Ethereum Name Service using five shuffled Ethereum endpoints, with a Tor hidden service fallback, so authorities cannot seize a domain or serve a takedown order. The botnet, powered mostly by hijacked Android TV boxes and IoT devices, previously had servers seized and an alleged operator arrested; new C2 infrastructure traces to a single network in Saint Petersburg, Russia. It is unclear whether the same developers built the new version.
Upatre Continued to Evolve with new Anti
Unit 42 analyzes an undocumented Upatre downloader variant with VM detection via process hashing, packed code, disabled Windows defenses and Namecoin .bit C2 domains.
Unit 42 analyzed an Upatre downloader variant compiled in December 2016 that went largely undetected by automated systems, featuring heavy code flow obscuration, on-demand decryption of network communications, and novel virtual machine detection. The sample enumerates running processes, computes CRC32 hashes XORed with a hard-coded key, and sleeps if analysis-related processes such as vmtoolsd.exe or python.exe are found. It masquerades with Google Chrome icons, disables Windows Defender, Firewall and other security services, injects code into msiexec.exe, and resolves .bit Namecoin domains like bookreader[.]bit via hardcoded OpenNIC DNS servers over TCP.
Cardinal RAT Sins Again, Targets Israeli Fin
Unit 42 documents updated Cardinal RAT attacks against Israeli FinTech firms, using BMP steganography, MD5-hash obfuscation, and process injection to hinder analysis and detection.
Unit 42 tracked a series of attacks using an updated Cardinal RAT (version 1.7.2) targeting the Israeli financial technology sector. The .NET loader hides a second-stage DLL inside an embedded BMP image decrypted with a single-byte XOR key, and the payload renames functions, methods, and variables to MD5 hashes for obfuscation. The malware installs a startup-folder LNK file and injects its final payload into RegSvcs.exe or RegAsm.exe, communicating with affiliatecollective[.]club over port 443. A possible relationship with the EVILNUM JavaScript malware used against similar organizations was also noted.