APT28 Unleashes the SkinnyBoy Malware

foudre malware

The Russian Advanced Persistent Threat (APT) group, tracked under the aliases APT28 or Fancy Bear, has recently released a new piece of malware into the wild. The malware, dubbed SkinnyBoy, was used against several government institutions in 2021. The criminals appear to have targeted entities associated with foreign affairs, military and defense, and foreign embassies. While some of the attacks targeted members of the European Union, the SkinnyBoy Malware was also discovered on compromised networks belonging to United States organizations.

But what does the SkinnyBoy Malware do exactly? This threat is typically delivered through a spear-phishing email, which carries a Microsoft Word document. While the file attachment may look legitimate, it actually packs a malicious script, which extracts and initializes a malware downloader. The criminals are likely to change their phishing email based on the recipient – they often pretended to notify the user of a pending invitation to an upcoming international event.

After the threat is deployed successfully, it will not launch immediately. Instead, the SkinnyBoy Malware will program Windows to start it the next time it boots up. The delayed execution is a typical trick that cybercriminals use to avoid detection. Once running, the SkinnyBoy Malware will utilize legitimate Windows features to fetch data about the compromised system's software configuration – systeminfo.exe and tasklist.exe. Apart from this, it will try to download and launch additional payloads, but so far, these have not been identified.

It seems that the SkinnyBoy Malware's primary focus is espionage and gaining more control over the compromised system/network. Thankfully, antivirus product vendors are already aware of the new threat, and the latest patches to their software should be more than enough to deter SkinnyBoy Malware's attack.

June 7, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.