Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security //

Ransomware

1/8/2019
08:15 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

New Malvertising Campaign Delivers Vidar Stealer Plus Ransomware

Malwarebytes Labs has uncovered a new malvertising campaign in the wild that delivers a one-two punch: the Vidar data stealer and GrandCrab ransomware.

A new "malvertising" campaign spotted in the wild is delivering a malicious one-two punch to victims: The first is the data stealer Vidar and the second is the GrandCrab ransomware strain, according to a recent report.

Researchers at Malwarebytes Labs first took notice of the malvertising campaign and published their findings in a January 4 blog post. It's not clear who is behind this particular attack or how widespread it is right now, but the report noted that the threat actors are essentially using off-the-shelf tools, including the Fallout exploit kit, which takes advantage of flaws in Adobe Flash and Microsoft Internet Explorer, to deliver these malicious payloads

This campaign has its origins in the advertising that usually accompanies torrent and streaming video. The person or group behind this particular campaign used this poorly regulated system to create a rogue advertising domain and redirect users to different exploit kits, including Fallout.

It's through these exploit kits that the one-two punch is delivered -- the stealer first followed by the ransomware.

At first, the researcher believed that the stealer being used was an older piece of malware called Arkei. However, further tests came up with Vidar, which has only been active since October 2018, but shares similarities with Arkei.

Vidar -- its name has origins in Norse mythology -- is written in C++ and it highly customizable. It has the capability to swipe and steal personal data from any number of web browsers, including Tor. Additionally, it can steal cryptocurrency wallets, data from two-factor authentication software, instant messages and much more, according to an independent analysis.

On the Dark Web, the Vidar kit can be bought for as little as $700.

However, when the researcher traced the campaign back to the command-and-control (C&C) server, they noticed that the attackers had a second malicious payload ready to be delivered once the Vidar stealer started its work.

"Vidar also offers to download additional malware via its command and control server," according to the Malwarebytes blog. "This is known as the loader feature, and again, it can be configured within Vidar's administration panel by adding a direct URL to the payload. However, not all instances of Vidar (tied to a profile ID) will download an additional payload. In that case, the server will send back a response of "ok" instead of a URL."

This then leads to the second part of the attack, GrandCrab, which is what some security researchers refer to as ransomware-as-service, as it relies on third-parties to help spread it. (See Kraken Cryptor Update Points to Rise of Ransomware-as-a-Service.)

Unlike other ransomware, GrandCrab is frequently updated -- the current version is 5.0.4 -- which helps it evade security software. Malwarebytes recommends that businesses update and patch IE and Flash to avoid this particular campaign before the ransomware can be downloaded.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5421
PUBLISHED: 2020-09-19
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
CVE-2020-8225
PUBLISHED: 2020-09-18
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVE-2020-8237
PUBLISHED: 2020-09-18
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
CVE-2020-8245
PUBLISHED: 2020-09-18
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11....
CVE-2020-8246
PUBLISHED: 2020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-W...