Technology

Witchetty Hacker group hides backdoor malware in Windows logo

Security researchers have discovered a new trick used by a hacker group called “Witchetty” to plant spyware on PC users. An image encryption process and an image of a Windows logo are used. That reports that Online magazine Bleeping Computer.

The new threat was reported by the security specialists at Symantec. In the campaign discovered by Symantec, the hackers exploit vulnerabilities discovered over the past year to break into the target network, taking advantage of the poor management of the public-facing servers. Infographic cyber attacks from the east: hackers target German companies

Well Disguised

The toolkit used to target various vulnerabilities uses steganography to hide its malicious payload from antivirus software. Steganography is the hiding of data in other, non-secret, public information or computer files, such as B. pictures to avoid detection. This allows a hacker to create a working image file that displays correctly on the computer, but also contains malicious code.

Malicious malware is hidden in the Windows logo

This is exactly the case with the attacks of the Witchetty group. They hid an XOR-encrypted backdoor malware in an old Windows logo bitmap image. The file is hosted on a trusted cloud service, so there will be no security alarm when retrieving the file. “By cloaking the payload in this way, the attackers could also host it on a free, trusted service,” explains Symantec in its report: “Downloads from trusted hosts like GitHub raise far fewer alarms than downloads from an attacker-controlled Command and Control (C&C) server.”

The attack begins with the attackers first gaining access to a network by exploiting the Microsoft Exchange ProxyShell and ProxyLogon attack chains. Once access is gained, further malware can be smuggled in. Witchetty is believed to have close ties to state-backed Chinese threat actor APT10. The group has also been linked to attacks on US utility companies. According to Symantec, hackers are currently targeting government institutions in particular.

Recent Posts

Encryption Essentials: What Every Cloud Storage User Should Know

What should we check before trusting important files to the cloud We often treat cloud…

29 minutes ago

Operation Bluebird: Twitter is back and controversy is inevitable

The social network Twitter is back in a new form: the US startup Operation Bluebird…

2 hours ago

Xbox Series X25: Price and date of the anniversary console leaked

The new Xbox Series X25 attracts fans with a chic green case in the style…

2 hours ago

Google Search, Discover and News: New options for personalization

Google is expanding personalization for its search, Discover feed and News. A new interactive button…

2 hours ago

GTA 6 leaks: Take-Two goes on a hacker hunt with subpoenas

Take-Two and Rockstar are using all possible means against the attackers operating under the name…

2 hours ago

Exchange Online 2026: Microsoft doubles mailbox storage

Microsoft is doubling the storage space for Exchange Online mailboxes in certain Microsoft 365 Business…

3 hours ago