New IceXLoader Malware Loader Variant Infected Thousands of Victims Worldwide

Teilen:

An updated version of a malware loader codenamed IceXLoader is suspected of having compromised thousands of personal and enterprise Windows machines across the world.

IceXLoader is a commodity malware that’s sold for $118 on underground forums for a lifetime license. It’s chiefly employed to download and execute additional malware on breached hosts.

This past June, Fortinet FortiGuard Labs said it uncovered a version of the trojan written in the Nim programming language with the goal of evading analysis and detection.

“While the version discovered in June (v3.0) looked like a work-in-progress, we recently observed a newer v3.3.3 loader which looks to be fully functionable and includes a multi-stage delivery chain,” Natalie Zargarov, cybersecurity researcher at Minerva Labs, sagte in a report published Tuesday.

IceXLoader is traditionally distributed through phishing campaigns, with emails containing ZIP archives functioning as a trigger to deploy the malware. Infection chains have leveraged IceXLoader to deliver DarkCrystal RAT and cryptocurrency miners.

Bild8 2

In the attack sequence detailed by Minerva Labs, the ZIP file has been found to harbor a dropper, which drops a .NET-based downloader that, as the name implies, downloads a PNG image (“Ejvffhop.png”) from a hard-coded URL.

This image file, another dropper, is subsequently converted into an array of bytes, effectively allowing it to decrypt and inject IceXLoader into a new process using a technique called process hollowing.

 

Version 3.3.3 of IceXLoader, like its predecessor, is written in Nim and is equipped to collect system metadata, all of which is exfiltrated to a remote attacker-controlled domain, while awaiting further commands issued by the server.

The commands include the ability to restart and uninstall the malware loader and halt its execution. But its main feature is to download and execute next-stage malware on disk or filelessly in memory.

Minerva Labs said a SQLite database file hosted in the command-and-control (C2) server is being continuously updated with information about thousands of victims, adding it’s in the process of notifying impacted companies.

https://thehackernews.com/2022/11/new-icexloader-malware-loader-variant.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:09 pm, Juli 8, 2025
Wetter-Symbol 23°C
L: 23° | H: 24°
broken clouds
Luftfeuchtigkeit: 37 %
Druck: 1018 mb
Wind: 10 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:53 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
23° | 24°°C 0 mm 0% 3 mph 38 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 25°°C 0.18 mm 18% 7 mph 57 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 29°°C 0 mm 0% 10 mph 65 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0 mm 0% 3 mph 38 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 3 mph 43 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 3 mph 50 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,055.49
0.96%
Ethereum(ETH)
€2,234.49
3.07%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.98
1.06%
Solana(SOL)
€130.15
1.74%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.145845
1.96%
Shiba Inu(SHIB)
€0.000010
3.00%
Pepe(PEPE)
€0.000009
2.69%
Nach oben scrollen