Technology

Witchetty Hacker group hides backdoor malware in Windows logo

Security researchers have discovered a new trick used by a hacker group called “Witchetty” to plant spyware on PC users. An image encryption process and an image of a Windows logo are used. That reports that Online magazine Bleeping Computer.

The new threat was reported by the security specialists at Symantec. In the campaign discovered by Symantec, the hackers exploit vulnerabilities discovered over the past year to break into the target network, taking advantage of the poor management of the public-facing servers. Infographic cyber attacks from the east: hackers target German companies

Well Disguised

The toolkit used to target various vulnerabilities uses steganography to hide its malicious payload from antivirus software. Steganography is the hiding of data in other, non-secret, public information or computer files, such as B. pictures to avoid detection. This allows a hacker to create a working image file that displays correctly on the computer, but also contains malicious code.

Malicious malware is hidden in the Windows logo

This is exactly the case with the attacks of the Witchetty group. They hid an XOR-encrypted backdoor malware in an old Windows logo bitmap image. The file is hosted on a trusted cloud service, so there will be no security alarm when retrieving the file. “By cloaking the payload in this way, the attackers could also host it on a free, trusted service,” explains Symantec in its report: “Downloads from trusted hosts like GitHub raise far fewer alarms than downloads from an attacker-controlled Command and Control (C&C) server.”

The attack begins with the attackers first gaining access to a network by exploiting the Microsoft Exchange ProxyShell and ProxyLogon attack chains. Once access is gained, further malware can be smuggled in. Witchetty is believed to have close ties to state-backed Chinese threat actor APT10. The group has also been linked to attacks on US utility companies. According to Symantec, hackers are currently targeting government institutions in particular.

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

32 minutes ago

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose…

36 minutes ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

36 minutes ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

38 minutes ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

39 minutes ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

40 minutes ago