Cybercriminals Renting WikiLoader to Target Italian Organizations with Banking Trojan

Teilen:

Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer, and spyware referred to as Ursnif (aka Gozi).

It is a sophisticated downloader with the objective of installing a second malware payload, Proofpoint said in a technical report. The malware uses multiple mechanisms to evade detection and was likely developed as a malware that can be rented out to select cybercriminal threat actors.

WikiLoader is so named due to the malware making a request to Wikipedia and checking that the response has the string The Free.

The enterprise security firm said it first detected the malware in the wild on December 27, 2022, in connection with an intrusion set mounted by a threat actor it tracks as TA544, which is also known as Bamboo Spider and Zeus Panda.

The campaigns are centered around the use of emails containing either Microsoft Excel, Microsoft OneNote, or PDF attachments that act as a lure to deploy the downloader, which is subsequently used to install Ursnif.

In a sign that WikiLoader is shared among multiple cybercrime groups, the threat actor dubbed TA551 (aka Shathak) has also been observed employing the malware as of late March 2023.

Recent TA544 campaigns detected in mid-July 2023 have utilized accounting themes to propagate PDF attachments with URLs that, when clicked, lead to the delivery of a ZIP archive file, which, in turn, packs a JavaScript file designed to download and execute WikiLoader.

WikiLoader is heavily obfuscated and comes with evasive maneuvers to bypass endpoint security software and avoid detonation in automated analysis environments. It’s also engineered to retrieve and run a shellcode payload hosted on Discord, which is ultimately used to launch Ursnif.

It is currently under active development, and its authors appear to make regular changes to try and remain undetected and fly under the radar, Selena Larson, senior threat intelligence analyst at Proofpoint, said in a statement.

It is likely more criminal threat actors will use this, especially those known as initial access brokers (IABs) that conduct regular activity that leads to ransomware. Defenders should be aware of this new malware and activities involved in payload delivery, and take steps to protect their organizations against exploitation.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:16 pm, Juni 1, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
broken clouds
Luftfeuchtigkeit: 47 %
Druck: 1013 mb
Wind: 11 mph W
Windböe: 20 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 14 mph 44 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 12 mph 50 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 31 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,772.33
0.42%
Ethereum(ETH)
€2,202.20
-0.98%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.89
-0.17%
Solana(SOL)
€133.97
-0.89%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.166779
0.94%
Shiba Inu(SHIB)
€0.000011
2.94%
Pepe(PEPE)
€0.000010
1.71%
Peanut das Eichhörnchen(PNUT)
€0.227225
4.08%
Nach oben scrollen