• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hackers exploit webview2 to deploy coinlurker malware and evade security

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection

You are here: Home / General Cyber Security News / Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection
December 17, 2024

Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker.

“Written in Go, CoinLurker employs cutting-edge obfuscation and anti-analysis techniques, making it a highly effective tool in modern cyber attacks,” Morphisec researcher Nadav Lorber said in a technical report published Monday.

The attacks make use of fake update alerts that employ various deceptive entry points such as software update notifications on compromised WordPress sites, malvertising redirects, phishing emails that link to spoofed update pages, fake CAPTCHA verification prompts, direct downloads from phoney or infected sites, and links shared via social media and messaging apps.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Regardless of the method utilized to trigger the infection chain, the software update prompts make use of Microsoft Edge Webview2 to trigger the execution of the payload.

Cybersecurity

“Webview2’s dependency on pre-installed components and user interaction complicates dynamic and sandbox analysis,” Lorber said. “Sandboxes often lack Webview2 or fail to replicate user actions, allowing the malware to evade automated detection.”

One of the advanced tactics adopted in these campaigns concerns the use of a technique called EtherHiding, in which the compromised sites are injected with scripts that are designed to reach out to Web3 infrastructure in order to retrieve the final payload from a Bitbucket repository that masquerades as legitimate tools (e.g., “UpdateMe.exe,” “SecurityPatch.exe”).

These executables, in turn, are signed with a legitimate-but-stolen Extended Validation (EV) certificate, thereby adding another layer of deception to the scheme and bypassing security guardrails. In the final step, the “multi-layered injector” is used to deploy the payload into the Microsoft Edge (“msedge.exe”) process.

CoinLurker also uses a clever design to conceal its actions and complicate analysis, including heavy obfuscation to check if the machine is already compromised, decoding the payload directly in memory during runtime, and taking steps to obscure the program execution path using conditional checks, redundant resource assignments and iterative memory manipulations.

“This approach ensures that the malware evades detection, blends seamlessly into legitimate system activity, and bypasses network security rules that rely on process behavior for filtering,” Morphisec noted.

CoinLurker, once launched, initiates communications with a remote server using a socket-based approach and proceeds to harvest data from specific directories associated with cryptocurrency wallets (namely, Bitcoin, Ethereum, Ledger Live, and Exodus), Telegram, Discord, and FileZilla.

“This comprehensive scanning underscores CoinLurker’s primary goal of harvesting valuable cryptocurrency-related data and user credentials,” Lorber said. “Its targeting of both mainstream and obscure wallets demonstrates its versatility and adaptability, making it a significant threat to users in the cryptocurrency ecosystem.”

The development comes as a single threat actor has been observed orchestrating as many as 10 malvertising campaigns that abuse Google Search ads to single out graphic design professionals since at least November 13, 2024, using lures related to FreeCAD, Rhinoceros 3D, Planner 5D, and Onshape.

Cybersecurity

“Domains have been launched day after day, week after week, since at least November 13, 2024, for malvertising campaigns hosted on two dedicated IP addresses: 185.11.61[.]243 and 185.147.124[.]110,” Silent Push said. “Sites stemming from these two IP ranges are being launched in Google Search advertising campaigns, and all lead to a variety of malicious downloads.”

It also follows the emergence of a new malware family dubbed I2PRAT that abuses the I2P peer-to-peer network for encrypted communications with a command-and-control (C2) server. It’s worth noting that I2PRAT is also tracked by Cofense under the name I2Parcae RAT.

The starting point of the attack is a phishing email containing a link that, when clicked, directs the message recipient to a fake CAPTCHA verification page, which employs the ClickFix technique to trick users into copying and executing a Base64-encoded PowerShell command responsible for launching a downloader, which then deploys the RAT after retrieving it from the C2 server over a TCP socket.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «the mask apt resurfaces with sophisticated multi platform malware arsenal The Mask APT Resurfaces with Sophisticated Multi-Platform Malware Arsenal
Next Post: 5 Practical Techniques for Effective Cyber Threat Hunting 5 practical techniques for effective cyber threat hunting»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.