RIG Exploit Kit Delivering RedLine Via Internet Explorer

RIG exploit kit

Researchers at Bitdefender have discovered a new campaign of cybercriminals using the RIG exploit kit to distribute the famous RedLine malware, which aims to steal victimsdata and transfer it to operators.

Interestingly, exploit kits like RIG, which used to be quite popular, are now increasingly fading into the shadows. And all thanks to improved browser protection mechanisms and the rejection ofleakytechnologies like Flash Player and Microsoft Silverlight.

Ωστόσο, attackers using exploit kits can still break through individual users who are used to not updating their browser. Για παράδειγμα, in the campaign described by Bitdefender, RIG delivers an info-stealer by exploiting a bug in Internet Explorer.

We are talking about a vulnerability under the identifier CVE-2021-26411, which leads to memory corruption when viewing a specially crafted website. If a user is lured to such a resource, the RedLine malware will be installed on their system.

BAAA Virus (.baaa File) Ransomware

BAAA Ransomware

The Baaa virus belongs to the STOP/Djvu ransomware group and targets Windows computers. Λειτουργεί κρυπτογραφώντας τα αρχεία σε αυτούς τους υπολογιστές, αλλάζοντας τα σε αρχεία με α “.Baaa” επέκταση,…

Ιός BGZQ (.Αρχείο bgzq) Ransomware

Bgzq Ransomware

The Bgzq virus belongs to the STOP/Djvu ransomware group and targets Windows computers. Λειτουργεί κρυπτογραφώντας τα αρχεία σε αυτούς τους υπολογιστές, αλλάζοντας τα σε αρχεία με α “.Bgzq” επέκταση,…

Having dug into the system, RedLine collects and sends confidential information to operators: keys from crypto wallets, bank card data, logins, and passwords saved in browsers.

According to Bitdefender researchers, the exploit first dumps a JavaScript file into the system (placed in a temporary directory), downloading and running an encrypted RC4 payload.

Decompressing RedLine is a six-step process consisting of decompression, key extraction, assembly, etc. As a result, files in the DLL format can successfully avoid detection by antivirus tools. The malware connects to the command and control server at 185.215.113.121 on port 15386. Data collected from VPN and FTP clients, Discord, Telegram, Steam, and crypto-wallets are also sent there.

Αφήστε ένα σχόλιο