Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV //

Malware

9/13/2018
09:35 AM
Jeffrey Burt
Jeffrey Burt
Jeffrey Burt
50%
50%

Cobalt Group Returns With Downloader Malware

Proofpoint found new campaigns by the notorious cybercrime gang using its CobInt modular downloader.

The Cobalt Group, which has made a name for itself over the past couple of years for stealing millions of dollars from banks and ATMs across Europe and Russia, is using a modular downloader in its latest campaign, according to researchers at security vendor Proofpoint.

The cybercriminal gang, which came onto the scene in 2016 primarily targeting financial institutions, is using malware that was dubbed "CobInt" by Group-IB when the Russian threat intelligence firm first detected the modular downloader. According to a blog post this week by the Proofpoint researchers, the Cobalt Group apparently stopped using CobInt as a first-stage downloader around the time Group-IB published its findings. However, it now seems the cybercrime group is back using CobInt, starting in July. Cobalt also was dealt a setback in March when the group's suspected leader was arrested.

Analysts at NetScout's Arbor Networks unit wrote about the return of CobInt last month, and now Proofpoint researchers note that they have found evidence of the Cobalt Gang's renewed effort with CobInt.

Email campaign designed to deliver CobInt malware\r\n(Source: Proofpoint)\r\n
Email campaign designed to deliver CobInt malware
\r\n(Source: Proofpoint)\r\n

"Threat actors that are trying to avoid attention will often pause their activities when they feel too many eyes on them," Bryan Burns, vice president of threat research and engineering at Proofpoint, told Security Now in an email. "Sometimes that means changing tools and payloads, or it may mean going dark entirely for a while. Sophisticated malware is a sizeable investment, however, so we often see it returning at a later date once the pressure is off."

CobInt is the latest modular downloader campaign Proofpoint has seen in recent weeks.

Earlier in the summer, researchers discovered Marap -- which targeted financial institutions -- and AdvisorsBot, which focused more on hotels, restaurants and telecommunications companies. Both downloader campaigns came with relatively small footprints, were designed to evade detection by cybersecurity solutions and were focused on reconnaissance of the infected systems, according to Proofpoint researchers. CobInt shares similar qualities. (See AZORult Downloader Adds Cryptomining, Ransomware Capabilities.)

Modular downloaders are designed to enable attackers to modify and update the software after it has been installed onto a victim's system.

"Modular downloaders give the threat actors more flexibility, subtlety, and control," Burns wrote. "By collecting data on the infected system, they can tailor the next payload to the victim to maximize returns or skip further infections entirely if the system doesn't match what they're after. Because these downloaders are relatively simple compared to a full Trojan or other final payload, they are easier to mutate and obfuscate to avoid detection."

Proofpoint researchers in August and September detected email campaigns designed to deliver the CobInt malware. The first, seen on August 2 and also detected by Arbor Networks, involved messages written in Russian with subject lines reading "Suspicion of fraud." The messages contained two URLs, with the first linked to a macro document that installed the downloader. The second URL linked directly to the CobInt Stage 1 executable.

The second round of messages were seen August 14 and spoofed the Single Euro Payments Area (SEPA) with sender domains that look legitimate. The subject lines used such words as "notification," "letter," "message" and "notice." These messages contained a Word document that was a ThreatKit exploit document that would execute the embedded CobInt Stage 1 payload. Some of the messages contained URLs linking directly to the CobInt downloader, the analysts said.

The CobInt downloader malware is written in C and can be seen in three stages. The first is an initial stage, which according to Proofpoint researchers, "is a basic downloader with the purpose of downloading the main CobInt component. As with other downloaders we have examined recently, its functionality is disguised by the use of Windows API function hashing. The command and control (C&C) host and URI are stored as encrypted strings."

The second stage is the main component, in which various modules from the C&C server are downloaded. The third stage follows with downloading and executing additional modules.

In their blog post, Proofpoint researchers note that CobInt shows that threat actors like the Cobalt Group and others "are increasingly looking to stealthy downloaders to initially infect systems and then only install additional malware on systems of interest."

Burn told Security Now that it also "tells us that collectively we are getting better at detecting and defending against these types of attacks. This is ultimately an arms race, and the attackers are evolving their tools to try to stay ahead of modern defenses. Also, with the spate of recent arrests and indictments against cyber-threat actors, there must be increased pressure to try to fly beneath the radar of the global intelligence community."

Related posts:

— Jeffrey Burt is a long-time tech journalist whose work has appeared in such publications as eWEEK, The Next Platform and Channelnomics.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Sure you have fire, but he has an i7!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27314
PUBLISHED: 2021-03-05
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
CVE-2019-18630
PUBLISHED: 2021-03-04
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.
CVE-2021-25344
PUBLISHED: 2021-03-04
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
CVE-2021-25345
PUBLISHED: 2021-03-04
Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.
CVE-2021-25346
PUBLISHED: 2021-03-04
A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.