NullMixer Malware Loader Delivers Malicious Files in Bulk
NullMixer is a newly discovered piece of malware that acts as a downloader for a number of other malicious files.
Security researchers examining NullMixer found it distributed primarily through websites that offer cracked software and "cracks" for paid programs and games.
The NullMixer payload is commonly found inside a password-protected archive file, with the password provided on the crack website. Once the user extracts and runs the executable, NullMixer downloads a number of additional malicious payloads.
The infection chain starts with several bad redirects that lead to an archive hosted on a free hosting website.
The NullMixer malware loader can download a scary number of additional malicious files on the victim system. The possible extra payloads include infostealers, backdoors and banking trojans such as Vidar stealer, Redline stealer and Smoke Loader.
Pirating software is never a good idea and with the increase in malicious tools distributed through crack sites, piracy is more dangerous than ever.