Automatically translated.View original post

Fake ads release malware in pieces.

The fake ad releases the malware in pieces and then has the web browser assemble it itself.

According to a report by the website, The Hacker News has mentioned the detection of a new campaign of Malvertising scams, a research team from Confiant, an online advertising security expert, published details of this campaign in the past 23 July, but the details reveal that the campaign has been running since 2024. In 2567), the campaign used impersonations of famous applications such as TradingView (the same as the famous Somchai Sae ad in Thailand earlier this year), Solana, and Luno, which will focus its attacks on small stock traders and Cryptocurrency traders, with a large scale campaign that uses up to 25 advertising languages in 12 countries around the world. What makes this campaign different from other malware release ads is that the malware does not come as a single payload file, but Bun Runtime. As a base, then slowly pull down the other components, and then instruct the web browser to make up the final Payload file.

The work of the campaign is very simple. After the victim clicks the advertised page, it will load the page and trick the victim to download it. While waiting for the victim to press the download button, the page will prepare to send the malware file to the victim. With the ServiceWorker registration at / sw.js, then create SharedWorker from JavaScript embedded on the page. The SharedWorker created will request / config. After the request is received, the SharedWorker will receive the template. (Template), the second Runtime URL, and the specific random value of the Session, and the open web browser itself will also download the second URL (purelogicbox [.org] and unpack the Decompressed Bun Runtime file.

Blobs encoded in Base64 within the setup section send Portable Executable (PE) Header, Section Table, and .bun data sections with Bytecode bytecode-code latency within JavaScriptCore for app.js. Bun will run on JavaScriptCore and support Bytecode compilation. Such malware is an Executable File on the Windows operating system. In the field of Executable file generation, the SharedWorker will create a random byte stream (Pudandom Bytam Stream). ) Large with AES in Counter Mode (AES-CTR) based on the formula contained within the template given above, along with the selected data range in Bun Runtime and other Executable file elements selected by the hackers behind it, eventually came out as a complete malware payload file. At this point, each victim will get the final files assembled differently, so that it is difficult for the system to detect them.

The assembled files have been completed. The web browser will auction (Passes) via ServiceWorker in Readable Stream format. The hidden iframe then navigates to the same source URL. At this stage, ServiceWorker will return the generated byte with a Header. Content-Disposition: attachment to make the Mark-on-the-Web (MotW) machine look at the landing page as a source for downloading the file (Download Source) instead of a domain that provides a separate Bun Runtime. It makes the successful files that the victim downloads (EXE files) come from files that are assembled on the web browser itself, not directly from the server, but everything is fake as if it were downloaded from the website's server as usual, so that the victim does not know. The research team confirmed that the hacker's fraudulent website is not hosted (Host). A single full EXE file is called a very complex and superb method, and this complexity makes it impossible for the research team to identify the names or types of clear malware that have been downloaded to the machine in this way at this time. Every item receives a unique final file and has completely different Hash data every time.

# Trending # lemon 8 diary # Advertising # Malware # freedomhack

8/18 Edited to

... Read moreการปล่อยมัลแวร์ผ่านโฆษณาปลอมแบบนี้ถือเป็นเทคนิคที่ซับซ้อนและน่ากลัวมาก เพราะแทนที่จะส่งไฟล์มัลแวร์แบบเต็ม ๆ มาให้เหยื่อโดยตรง ตัวมัลแวร์จะถูกแบ่งเป็นส่วนย่อย ๆ ที่เว็บเบราว์เซอร์ต้องค่อย ๆ ประกอบไฟล์ขึ้นมาเอง จึงทำให้ระบบตรวจจับแบบเดิม ๆ ตรวจจับได้ยากมาก ผมเองเคยพบว่าในช่วงเวลาที่ใช้อินเทอร์เน็ตและเห็นโฆษณาที่เกี่ยวข้องกับการลงทุนหรือเทรดคริปโต หากไม่ระวังคลิกบ่อย ๆ อาจโดนเบนแบบนี้เข้าได้แบบไม่รู้ตัว วิธีป้องกันเบื้องต้นคือหลีกเลี่ยงการคลิกโฆษณาที่น่าสงสัย รวมถึงติดตั้งโปรแกรมแอนตี้มัลแวร์ที่อัปเดตอยู่เสมอ และตั้งค่าความปลอดภัยของเบราว์เซอร์ให้เข้มงวด เรื่องของการใช้ ServiceWorker และ SharedWorker ในการดาวน์โหลดและประกอบมัลแวร์นี่น่าสนใจมาก เพราะเทคนิคนี้ใช้ประโยชน์จากฟีเจอร์ของเว็บเบราว์เซอร์สมัยใหม่เพื่อลดโอกาสถูกตรวจจับ นอกจากนี้ การเข้ารหัสข้อมูลเป็น base64 และการสร้าง byte stream แบบสุ่มด้วย AES-CTR ยังช่วยให้ไฟล์ที่ได้แตกต่างกันในแต่ละเครื่อง จึงยากต่อการวิเคราะห์จากนักวิจัยความปลอดภัยด้วย สำหรับคนทั่วไป การไม่ดาวน์โหลดไฟล์จากแหล่งที่ไม่น่าเชื่อถือ การระมัดระวังไม่คลิกลิงก์ในโฆษณาที่ไม่น่าไว้ใจ และติดตั้งแอนติไวรัสที่มีการอัปเดตสม่ำเสมอ ถือเป็นแนวทางที่ดีที่สุดในการลดความเสี่ยงที่จะโดนโจมตีแบบนี้ รวมถึงควรศึกษาและติดตามข่าวสารด้านความปลอดภัยไซเบอร์บ่อย ๆ เพื่อรับมือกับวิธีการใหม่ ๆ ที่แฮกเกอร์พัฒนาขึ้นเรื่อย ๆ ท้ายที่สุด ความรู้และความระมัดระวังในการใช้อินเทอร์เน็ต เป็นเกราะป้องกันที่สำคัญที่สุดในการรักษาความปลอดภัยให้ตัวเองและข้อมูลสำคัญของเราไม่ให้ถูกมัลแวร์และการโจมตีทางไซเบอร์เล่นงานได้ง่าย ๆ