Malicious Advertising Campaign Distributing FormBook Info-Stealer Malware

Risk:
high
Damage:
high
Platform(s):
Web Servers Systems Networks
Advisory ID:
ngCERT-2023-0005
Version:
N/A
CVE:
N/A
Published:
February 13, 2023

Summary


Cybercriminals are constantly seeking and coming up with new ways to distribute malware – with the latest method being through malicious advertisements. These malicious advertising, or malvertising campaign are used to spread .NET loaders, known as MalVirt, that deploy the FormBook information-stealing malware unto unsuspecting devices.

Description & Consequence


Malvertising can appear on any advertisement on any website, including those you visit on a regular basis. Malvertising typically installs a small piece of code that connects your computer to criminal command and control (C&C) servers. The server searches your computer for its location and what software is installed on it before deciding which malware to send you. In this campaign, malvertising is the most common method of distribution, which involves inserting malicious advertisements into popular search engines when unsuspecting users conduct searches. By clicking on such a link, a device will be infected with the MalVirt loader, which uses a KoiVM virtualizing protector to avoid detection and analysis by anti-malware software. The loader will then install the FormBook malware and a signed Microsoft Process Explorer driver, allowing it to perform actions with elevated privileges. FormBook can also hide its C2 (command and control) traffic behind bogus HTTP requests to various dummy domains.

The FormBook malware is capable of keylogging, taking screenshots, stealing sensitive credentials from the web browser, and inserting other malware, among other things.

Solution


To avoid falling victim:

  1. Refrain from clicking on arbitrary advertising links.
  2. Install reliable anti-malware software.
  3. Keep operating system and anti-virus up-to-date.
  4. Run regular and schedules security scans.

Reference


Revision


Related Articles