New CMoon USB worm targets Russians in data theft attacks

Share:

A new self-spreading worm named ‘CMoon,’ capable of stealing account credentials and other data, has been distributed in Russia since early July 2024 via a compromised gas supply company website.

According to Kaspersky researchers who discovered the campaign, CMoon can perform a broad range of functions, including loading additional payloads, snapping screenshots, and launching distributed denial of service (DDoS) attacks.

Judging from the distribution channel the threat actors used, their targeting scope is focused on high-value targets rather than random internet users, which indicates a sophisticated operation.

Distribution mechanism

Kaspersky says the infection chain begins when users click on links to regulatory documents (docx, .xlsx, .rtf, and .pdf) found on various pages of a company’s website that provides gasification and gas supply services to a Russian city.

The threat actors replaced the document links with links to malicious executables, which were also hosted on the site and delivered to the victims as self-extracting archives containing the original document and the CMoon payload, named after the original link.

“We have not seen other vectors of distribution of this malware, so we believe that the attack is aimed only at visitors to the particular site,” reports Kaspersky.

After the gas firm was notified of this compromise, the malicious files and links were removed from its website on July 25, 2024.

However, due to CMoon’s self-propagation mechanisms, its distribution may continue autonomously.

CMoon is a .NET worm that copies itself to a newly created folder named after the antivirus software it detected on the compromised device or one resembling a system folder if no AVs are detected.

The worm creates a shortcut on the Windows Startup directory to ensure it runs on system startup, securing persistence between reboots.

To avoid raising suspicions during manual user checks, it alters its files’ creation and modification dates to May 22, 2013.

The worm monitors for newly connected USB drives, and when any are hooked up on the infected machine, it replaces all files except for ‘LNKs’ and ‘EXEs’ with shortcuts to its executable.

CMoon also looks for interesting files stored on the USB drives and temporarily stores them in hidden directories (‘.intelligence’ and ‘.usb’) before these are exfiltrated to the attacker’s server.

CMoon features standard info-stealer functionality, targeting cryptocurrency wallets, data stored in web browsers, messenger apps, FTP and SSH clients, and document files in the USB or user folders that contain the text strings ‘secret,’ ‘service,’ or ‘password.’

An interesting and somewhat unusual feature is the targeting of files that might contain account credentials such as .pfx, .p12, .kdb, .kdbx, .lastpass, .psafe3, .pem, .key, .private, .asc, .gpg, .ovpn, and .log files.

The malware can also download and execute additional payloads, capture screenshots of the breached device, and initiate DDoS attacks on specified targets.

Stolen files and system information are packaged and sent to an external server, where they are decrypted (RC4) and verified for their integrity using an MD5 hash.

Kaspersky leaves open the possibility of more sites outside its current visibility distributing CMoon, so vigilance is advised.

No matter how targeted this campaign may be, the fact that the worm spreads autonomously means it could reach unintended systems and create the conditions for opportunistic attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:56 pm, Jun 21, 2025
weather icon 25°C
L: 24° | H: 26°
broken clouds
Humidity: 52 %
Pressure: 1013 mb
Wind: 14 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 59%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
24° | 26°°C 0.25 mm 25% 16 mph 64 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 80 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 14 mph 80 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 28°°C 0.21 mm 21% 10 mph 85 % 1014 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
16° | 20°°C 1 mm 100% 12 mph 95 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 24°°C 0.2 mm 20% 8 mph 54 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 20°°C 0.25 mm 25% 9 mph 64 % 1013 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 64 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 12 mph 49 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 34 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 16 mph 41 % 1012 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 59 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€88,253.76
-1.82%
Ethereum(ETH)
€1,994.35
-5.18%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.78
-3.73%
Solana(SOL)
€115.95
-4.96%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132678
-6.26%
Shiba Inu(SHIB)
€0.000010
-5.26%
Pepe(PEPE)
€0.000008
-6.87%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top