They say piracy killed the Amiga. Know what else it's killing? Malware sales. Awww, diddums

Trojan devs give up after seeing hard work ripped off, copied between crooks

BSides LV Life’s tough as a malware developer. If the cops or Feds don't collar you, your fellow scumbags will screw you over – or perhaps both will happen.

In a presentation at the Bsides Las Vegas hacking conference today, Winnona DeSombre, an analyst at threat-intelligence biz Recorded Future, detailed a year-long probe into dark and public web forums and chat rooms where malware writers hang out. What she saw, during the course of the investigation that ended May 2019, was a constant fight between people who write malware and those who crack it and sell it on themselves or just give it away.

Software nasties are pirated by crooks and redistributed just like legit applications, in other words. Malware development is not immune to piracy.

“Piracy is bad, you should never do it,” said DeSombre, somewhat tongue in cheek, as she explained how it‘s causing a headache for malware authors.

By way of example, she laid out the rise and fall of a trojan called AZORult, which harvests passwords, cookies, web browsing histories, and other personal data from infected Windows computers. It is typically used as a second stage – ie: it’s deployed once a computer is already compromised to thoroughly vacuum up information. AZORult could be purchased from its creator, and proved so popular that pirates weighed anchor and sailed off with a cracked version of it.

The first bootleg versions started to appear a few months after the initial release, when parts of the source code leaked. The original creator updated the software, adding new features and faster data exfiltration, but the pirates moved in again and released their own updated version, and finally the original seller quit the market.

Confession: I was a teenage computer virus writer


Cracked malware, as you can imagine, was rather popular on these underground forums, DeSombre said, and cut into the sales and revenue of professional malware writers who treated their malicious code to regular feature updates, bug fixes, and user support.

She also noted that malware writers exploit the media to push their products. She revealed forum postings advertising software nasties that linked to articles by security journalists reporting on that very malware. The developers of the devilish code hoped to use the news coverage to show off their creations' influence and power. It was all part of the buzz-generation machine malware sellers used to flog their software.

Another popular tactic by malware vendors is search engine optimization (SEO). Sellers crafted packages or bundles of malware for SEO purposes, listing off as many components as possible to catch all the keywords and appear high in search results, even adding free code to sweeten the pot. It was, and still is, all about selling code to script kiddies as quickly as possible.

You may be interested to know that a lot of the ransomware, trojans, and similar gremlins discussed by hacker forums are old, in some cases more than three years old, and are defeated by installing the latest security patches from operating system vendors and other software makers. In other words, aging file-scrambling malware that rely on vulnerabilities for which patches have been available for months or years are pwning victims, and not elite zero-day-exploiting tools fresh out of the compiler.

A case in point is the njRAT trojan, which first surfaced in 2012. Despite its age, and the fact that most antivirus software kills it on sight, the malware is still immensely talked about and sold online.

“njRAT, for some reason, is going to be popular until the end of time,” DeSombre noted. ®

Similar topics

Other stories you might like

  • Symantec: More malware operators moving in to exploit Follina
    Meanwhile Microsoft still hasn't patched the fatal flaw

    While enterprises are still waiting for Microsoft to issue a fix for the critical "Follina" vulnerability in Windows, yet more malware operators are moving in to exploit it.

    Microsoft late last month acknowledged the remote code execution (RCE) vulnerability – tracked as CVE-2022-30190 – but has yet to deliver a patch for it. The company has outlined workarounds that can be used until a fix becomes available.

    In the meantime, reports of active exploits of the flaw continue to surface. Analysts with Proofpoint's Threat Insight team earlier this month tweeted about a phishing campaign, possibly aligned with a nation-state targeting US and European Union agencies, which uses Follina. The Proofpoint researchers said the malicious spam messages were sent to fewer than 10 Proofpoint product users.

    Continue reading
  • Chinese-sponsored gang Gallium upgrades to sneaky PingPull RAT
    Broadens targets from telecoms to finance and government orgs

    The Gallium group, believed to be a Chinese state-sponsored team, is going on the warpath with an upgraded remote access trojan (RAT) that threat hunters say is difficult to detect.

    The deployment of this "PingPull" RAT comes as the gang is broadening the types of organizations in its sights from telecommunications companies to financial services firms and government entities across Asia, Southeast Asia, Europe and Africa, according to researchers with Palo Alto Networks' Unit 42 threat intelligence group.

    The backdoor, once in a compromised system, comes in three variants, each of which can communicate with the command-and-control (C2) system in one of three protocols: ICMP, HTTPS and raw TCP. All three PingPull variants have the same functionality, but each creates a custom string of code that it sends to the C2 server, which will use the unique string to identify the compromised system.

    Continue reading
  • EnemyBot malware adds enterprise flaws to exploit arsenal
    Fast-evolving botnet targets critical VMware, F5 BIG-IP bugs, we're told

    The botnet malware EnemyBot has added exploits to its arsenal, allowing it to infect and spread from enterprise-grade gear.

    What's worse, EnemyBot's core source code, minus its exploits, can be found on GitHub, so any miscreant can use the malware to start crafting their own outbreaks of this software nasty.

    The group behind EnemyBot is Keksec, a collection of experienced developers, also known as Nero and Freakout, that have been around since 2016 and have launched a number of Linux- and Windows-based bots capable of launching distributed denial-of-service (DDoS) attacks and possibly mining cryptocurrency. Securonix first wrote about EnemyBot in March.

    Continue reading
  • Clipminer rakes in $1.7m in crypto hijacking scam
    Crooks divert transactions to own wallets while running mining on the side

    A crew using malware that performs cryptomining and clipboard-hacking operations have made off with at least $1.7 million in stolen cryptocurrency.

    The malware, dubbed Trojan.Clipminer, leverages the compute power of compromised systems to mine for cryptocurrency as well as identify crypto-wallet addresses in clipboard text and replace it to redirect transactions, according to researchers with Symantec's Threat Intelligence Team.

    The first samples of the Windows malware appeared in January 2021 and began to accelerate in their spread the following month, the Symantec researchers wrote in a blog post this week. They also observed that there are several design similarities between Clipminer and KryptoCibule – another cryptomining trojan that, a few months before Clipminer hit the scene, was detected and written about by ESET analysts.

    Continue reading

Biting the hand that feeds IT © 1998–2022