TeamTNT Cloaks Malware With Open-Source Tool
#1
Information 
Quote:The TeamTNT threat group has added a new detection-evasion tool to its arsenal, helping its cryptomining malware skirt by defense teams.

The new detection-evasion tool, libprocesshider, is copied from open-source repositories. The open-source tool, from 2014 has been located on Github, and is described as having capabilities to “hide a process under Linux using the ld preloader.”
 
“While the new functionality of libprocesshider is to evade detection and other basic functions, it acts as an indicator to consider when hunting for malicious activity on the host level,” said researchers with AT&T’s Alien Labs, on Wednesday.
 
The new tool is delivered within a base64-encoded script, hidden in the TeamTNT cryptominer binary, or via its Internet Relay Chat (IRC) bot, called TNTbotinger, which is capable of distributed denial of service (DDoS) attacks.
 
In the attack chain, after the base64-encoded script is downloaded, it runs through multiple tasks. These include modifying the network DNS configuration, setting persistence (through systemd), downloading the latest IRC bot configuration, clearing evidence of activities – and dropping and activating libprocesshider. [...]

Read more: https://threatpost.com/teamtnt-cloaks-ma...ol/163414/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Thunderbird 147.0.2 & 140.7.2esr
Thunderbird Versio...harlan4096 — 16:52
qBittorrent 5.1.4
qBittorrent 5.1.4:...harlan4096 — 16:48
Mozilla Firefox Browser 126.0.1
Firefox 147.0.4 al...harlan4096 — 16:47
Notepad++ 8.9.2
Notepad++ v8.9.2 R...harlan4096 — 16:46
Sandboxie 1.17.0 / 5.72.0
Sandboxie 1.17.0 /...harlan4096 — 16:45

[-]
Birthdays
Today's Birthdays
avatar (27)RaseinsLikes
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (39)TranoTymn
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>