Automatically translated.View original post

Hackers use PyInstaller to hide Xworm malware

Hackers use PyInstaller to hide Xworm malware inside and then fake it as a fake update to fool the victim.

According to a report by the SCWorld website, a research team from Point Wild has detected hackers using PyInstaller's developer tool to hack Xworm malware inside harmless files. Hackers take the files they use as carriers and insert the malware code with PyInstaller to create an Executable file from the script file. This will result in the victim opening the file feeling unnoticed, while in the background the malware is installed according to the inserted script, while the malware insert can emanate the detection system. The bait machine, too.

Within the code, the research team detected a Dummy code called "_ IAT _ PHANTOM _ FIX," which is expected to resist anti-analysis by malware analytics tools, and also to shut down the Windows virus scan system called Antimalware Scan Interface (AMSI) with the use of AMSI Memory Patching.

For the payload, hidden within the file, after it is released from the carrier file, it hides inside the% LOCALAPPDATA% folder on the victim's system under a file name that looks like a common file, such as "Win.Kernel _ Svc _ AJ8iOw.exe," and hides it. The malware file itself is mixed with other system files by the XWorm V7.4 malware. After successfully embedding it, it will contact the C2 or Command Control server with an AES encrypted Secret Key to receive attack commands. Attacking the victim's system ranges from stealing passwords, smuggling files on the machine, secretly using a webcam to spy on the victim, to using the victim's machine as part of a larger system shooting or DDoS (Distributed Denial-of-Service).

# Trending # Lemon 8 Howtoo # lemon 8 diary # Pylnataller # freedomhack

6/11 Edited to

... Read moreจากประสบการณ์ส่วนตัว ผมมักจะเห็นข่าวแฮกเกอร์ใช้เทคนิคขั้นสูงในการปลอมไฟล์เพื่อหลีกเลี่ยงการตรวจจับมัลแวร์ การใช้ PyInstaller เป็นวิธีที่แฮกเกอร์เลือกมาเพื่อซ่อนมัลแวร์ Xworm ซึ่งเป็นภัยร้ายแรง เพราะมันทำให้ไฟล์มัลแวร์ดูเหมือนไฟล์ธรรมดาที่ปลอดภัย จึงทำให้ผู้ใช้ทั่วไปเปิดใช้งานโดยไม่รู้ตัว สิ่งที่น่ากังวลคือมัลแวร์ตัวนี้มีการปิดระบบสแกนไวรัส AMSI ใน Windows ด้วยวิธี AMSI Memory Patching ซึ่งทำให้มัลแวร์นี้แทบจะซ่อนตัวได้เนียนกริบ อีกทั้งยังใช้โค้ดลวงชื่อ "_IAT_PHANTOM_FIX" ที่ช่วยให้แฮกเกอร์ตรวจจับและหลบหลีกการวิเคราะห์โค้ด ทำให้ผู้เชี่ยวชาญด้านความปลอดภัยต้องใช้วิธีวิเคราะห์ที่ซับซ้อนมากขึ้น ในขั้นตอนการทำงาน มัลแวร์จะซ่อนตัวในโฟลเดอร์ %LOCALAPPDATA% และใช้ชื่อไฟล์ที่ดูเหมือนไฟล์ระบบปกติ เช่น "Win.Kernel_Svc_AJ8iOw.exe" เพื่อหลอกให้เหยื่อไม่สงสัย ซึ่งเทคนิคการซ่อนไฟล์แบบนี้ทำให้การตรวจพบไฟล์มัลแวร์ยากขึ้นมาก ความสามารถของ Xworm V7.4 ไม่ได้จำกัดแค่การขโมยรหัสผ่านหรือข้อมูลส่วนตัวเท่านั้น แต่ยังสามารถเปิดใช้งานกล้องเว็บแคมเพื่อสอดแนม และใช้คอมพิวเตอร์ของเหยื่อในการโจมตีระบบอื่น ๆ ผ่านการโจมตีแบบ DDoS ซึ่งเป็นอันตรายอย่างมากสำหรับทั้งบุคคลและองค์กร จากประสบการณ์ ผมแนะนำว่าผู้ใช้ทุกคนควรระมัดระวังในการดาวน์โหลดและเปิดไฟล์โดยเฉพาะไฟล์ที่ได้รับจากแหล่งที่ไม่น่าเชื่อถือ รวมถึงต้องอัปเดตซอฟต์แวร์และระบบความปลอดภัยอย่างสม่ำเสมอ และใช้โปรแกรมแอนตี้ไวรัสที่มีความสามารถตรวจจับภัยไซเบอร์สมัยใหม่ที่สามารถจับพฤติกรรมมัลแวร์แบบนี้ได้อย่างมีประสิทธิภาพ ยิ่งในยุคที่แฮกเกอร์พัฒนาเทคนิคหลบเลี่ยงมากขึ้น ผู้ใช้ต้องเพิ่มความรู้และความระมัดระวังสูงสุดในการรับมือภัยคุกคามดังกล่าว