Campaign Evolution: EITest from October through December 2016
Unit 42 details the EITest campaign's late-2016 changes: gates and obfuscation dropped, with Rig EK variants delivering ransomware and infostealers.
Unit 42 tracks the EITest campaign through late 2016, noting it abandoned the gate between compromised websites and exploit kit landing pages after its October 2016 report, and stopped obfuscating injected script URLs by October 15. The campaign primarily uses the Rig-E (Empire Pack) variant and sometimes Rig-V of Rig EK to deliver Cerber and CryptoMix ransomware plus infostealers such as Gootkit, the Chthonic banking Trojan, Ursnif variants, and Latentbot. Tracked since 2014 by Malwarebytes Labs and others, EITest targets unpatched Windows systems without specific victimology.
EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Unit 42 details the EITest campaign's shift from Angler to Neutrino and Rig exploit kits while distributing ransomware, downloaders, and banking trojans.
Unit 42 updated its tracking of the EITest campaign, first identified in October 2014, which compromises websites with injected scripts that redirect victims through a gate to exploit kits. After Angler EK disappeared in June 2016, EITest switched to Neutrino and then primarily used Rig EK by August 2016. In September 2016 the campaign began using hex-obfuscated JavaScript and simplified gate URLs, while continuing to distribute payloads including Gootkit, Cerber, Bart, CryptFile2, Vawtrak, Ursnif, and Tinba. Gate infrastructure consistently reused IP blocks such as 85.93.0.0/24 even as domain names changed.
New Agent Tesla Malware Variant Boosts Evasion Capabilities
KnowBe4 documented an Agent Tesla v4 campaign using emoji-based code obfuscation to evade detection.
KnowBe4 researchers reported a campaign distributing Agent Tesla v4, a long-running Windows keylogger and infostealer. The new variant uses emoji-based code obfuscation, a novel technique, to hinder static analysis and evade security tooling. Defenders should watch for behavioral indicators such as credential theft and unusual process activity.
Campaign Evolution: pseudo
Unit 42 traces the pseudo-Darkleech campaign's 2016 shift from Angler to Neutrino to Rig exploit kits and rotating ransomware payloads.
Unit 42 documents how the pseudo-Darkleech exploit kit campaign evolved through 2016, switching from Angler EK to Neutrino EK in June and to Rig EK in September after Neutrino ceased operations. Payloads rotated from TeslaCrypt to CryptXXX, CrypMIC, and finally Cerber ransomware by October 2016. Injected script on compromised websites changed from 12,000-18,000 character obfuscated blocks to short, unobfuscated hidden iframes starting July 1, 2016.
Upatre Continued to Evolve with new Anti
Unit 42 analyzes an undocumented Upatre downloader variant with VM detection via process hashing, packed code, disabled Windows defenses and Namecoin .bit C2 domains.
Unit 42 analyzed an Upatre downloader variant compiled in December 2016 that went largely undetected by automated systems, featuring heavy code flow obscuration, on-demand decryption of network communications, and novel virtual machine detection. The sample enumerates running processes, computes CRC32 hashes XORed with a hard-coded key, and sleeps if analysis-related processes such as vmtoolsd.exe or python.exe are found. It masquerades with Google Chrome icons, disables Windows Defender, Firewall and other security services, injects code into msiexec.exe, and resolves .bit Namecoin domains like bookreader[.]bit via hardcoded OpenNIC DNS servers over TCP.
Trends in Web Threats: Old Web Skimmer Still Active Today
Unit 42 detected 577,000 landing URL incidents in Q1 2022, with an old web skimmer family still actively stealing payment card data.
Palo Alto Unit 42 detected 577,275 landing URL incidents (116,643 unique) and 2,043,862 malicious host URL incidents (180,370 unique) between January and March 2022. Web threat volumes declined after the November 2021 holiday peak, but an old web skimmer family remained active. Business and economy sites overtook personal sites as the most common apparently benign entry points. Most malicious domains geolocated to the United States, Germany, and Russia, though proxy servers and VPNs obscure true locations.