WailingCrab Malware Distributed Through Email Campaign

trojan horse malware

Emails with a delivery and shipping theme are being employed to distribute a sophisticated malware loader known as WailingCrab. According to researchers from IBM X-Force, the malware comprises various components, including a loader, injector, downloader, and backdoor. Successful interactions with command-and-control (C2) servers are crucial for progressing to the next stage.

Initially identified by Proofpoint in August 2023 and also referred to as WikiLoader, WailingCrab was utilized in campaigns targeting Italian organizations to deploy the Ursnif (aka Gozi) trojan. The malware, attributed to threat actor TA544 or Bamboo Spider/Zeus Panda, is managed by the cluster named Hive0133.

This malware, actively maintained by its operators, incorporates features that prioritize stealth and hinder analysis efforts. To evade detection, legitimate compromised websites are employed for initial C2 communications. Notably, components of the malware are stored on popular platforms like Discord. Since mid-2023, a significant change is the adoption of MQTT, a lightweight messaging protocol, for C2, which is a rarity in the threat landscape.

WailingCrab's Infection Chain

The attack sequence initiates with emails containing PDF attachments and URLs. Clicking these URLs triggers the download of a JavaScript file, initiating the WailingCrab loader on Discord. The loader launches a shellcode, which activates an injector module, leading to the deployment of a downloader that ultimately installs the backdoor.

The latest WailingCrab version encrypts the backdoor component with AES and communicates with its C2 to obtain a decryption key. The backdoor, serving as the malware's core, establishes persistence on the infected host and communicates with the C2 server using the MQTT protocol to receive additional payloads. Furthermore, recent variants of the backdoor opt for a shellcode-based payload directly from the C2 via MQTT, abandoning the previous Discord-based download path.

November 24, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.