🚨 Malware Campaign Alert: Unraveling the Complexity of a Malware Symphony - CrackedCantil 🚨
Summary:
A deep dive into the intricate world of malware collaboration, the CrackedCantil symphony orchestrates a malevolent ensemble, featuring loaders, infostealers, cryptominers, proxy bots, and ransomware. Understanding the symphony's composition reveals a chain of orchestrated chaos, from cracked software lures to devastating system compromise.
Malware:
Loaders: PrivateLoader, Smoke
Infostealers: Lumma, RedLine, RisePro, Amadey, Stealc
Cryptominers: Unspecified
Proxy Bot Malware: Socks5Systemz
Targeted Applications/CVEs:
Cracked Software: IDA Pro (specific version not mentioned)
Browser Hijacker: AT&T credentials phishing via myattwg.att[.]com
Impact:
Data Compromise, System Resource Drain, Proxy Bot Creation,
File Encryption, disrupting the system.
Indicators of Compromise (IOCs)
Ip_Addresses:
None
Domains:
None
URL:
hxxps://groups[.]google[.]com/g/exhibitor-users/c/eQTt-Z_Bnbw
hxxps://byltly[.]com/2wIwtU
hxxps://airfiltersing[.]com/CRACK IDA Pro V6 8 150423 And HEX-Rays Decompiler ARM X86 X64-iDAPROl[.]zip
hxxps://afashionstudio[.]com/b/release[.]rar
Hashes:
MD5:
57AB5E01E6E92D13AE33E587004AD918
DF1CA8FEDCF81BC2A5E456465E56FCEF
EF5C1EC128AC1822358D9281DCF3B710
0099A99F5FFB3C3AE78AF0084136FAB3
E8EB594C3BB064E91514C6A9C93B22FF
C6570BB5720D82B807160D350D83EE07
89F6A0761EB024C46520A74ABB7868A9
MITRE TTP IDs:
TA0002, T1204, T1053
TA0003, T1053, T1547
TA0004, T1053, T1547
TA0005, T1497, T1562, T1070
TA0006, T1552, T1555
TA0007, T1497, T1518, T1012, T1082
TA0011, T1071, T1571
TA0040, T1486
Reference: This writing is based on Research Advisory Report published by 'AnyRun' Team .
---------------------------------------------------------------------------------------
🚀Join us on our mission to secure the digital world and make cyber defense affordable to everyone! 🌐 Follow "CyberXTron Technologies" for the timely, relevant and actionable cyber threat insights.
#CrackedCantil #Cracked_Software #Browser_Hijacker #
#MalwareAttacks #cyberXTron #uncovertheunknown 🛡️🔒