• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hackers using new malware packer dtpacker to avoid analysis, detection

Hackers Using New Malware Packer DTPacker to Avoid Analysis, Detection

You are here: Home / General Cyber Security News / Hackers Using New Malware Packer DTPacker to Avoid Analysis, Detection
January 25, 2022

A previously undocumented malware packer named DTPacker has been noticed distributing numerous remote entry trojans (RATs) and details stealers such as Agent Tesla, Ave Maria, AsyncRAT, and FormBook to plunder details and facilitate comply with-on attacks.

“The malware employs a number of obfuscation strategies to evade antivirus, sandboxing, and examination,” enterprise security company Proofpoint explained in an evaluation printed Monday. “It is likely dispersed on underground community forums.”

Automatic GitHub Backups

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The .NET-primarily based commodity malware has been associated with dozens of campaigns and many danger teams, both sophisticated persistent threat (APT) and cybercrime actors, considering the fact that 2020, with the intrusions aimed at hundreds of consumers across quite a few sectors.

Attack chains involving the packer depend on phishing e-mail as an first an infection vector. The messages incorporate a destructive document or a compressed executable attachment, which, when opened, deploys the packer to launch the malware.

Malware Packer

Packers vary from downloaders in that contrary to the latter, they carry an obfuscated payload to hide their real behavior from security options in a method that acts as an “armor to secure the binary” and make reverse engineering extra tricky.

What can make DTPacker different is that it functions as the two. Its name is derived from the point that it utilized two Donald Trump-themed fixed keys — “trump2020” and “Trump2026” — to decode the embedded or downloaded source that ultimately extracts and executes the closing payload.

Prevent Data Breaches

It really is now not recognized why the authors chose this certain reference to the previous U.S. president as the malware is neither made use of to focus on politicians or political companies nor are the keys found by the focused victims.

Proofpoint said it observed the operators making subtle adjustments by switching to utilizing soccer fan club sites as decoys to host the malware from March 2021, with the packer used by teams like TA2536 and TA2715 in their very own campaigns a 12 months prior to that.

“DTPacker’s use as each a packer and downloader and its variation in shipping and obfuscation whilst preserving two these types of special keys as component of its decoding is very uncommon,” reported the researchers, who assume the malware to be employed by several menace actors for the foreseeable potential.

Uncovered this report intriguing? Stick to THN on Fb, Twitter  and LinkedIn to examine much more exclusive information we post.


Some elements of this report are sourced from:
thehackernews.com

Previous Post: «linux servers at risk of rce due to critical cwp Linux Servers at Risk of RCE Due to Critical CWP Bugs
Next Post: Mobile Banking Trojan BRATA Gains New, Dangerous Capabilities mobile banking trojan brata gains new, dangerous capabilities»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Microsoft Uncovers Banking AitM Phishing and BEC Attacks Targeting Financial Giants
  • University of Manchester Suffers Suspected Data Breach During Cyber Incident
  • Asylum Ambuscade: A Cybercrime Group with Espionage Ambitions
  • Barracuda Urges Swift Replacement of Vulnerable ESG Appliances
  • Google Launches Framework to Secure Generative AI
  • 5 Reasons Why Access Management is the Key to Securing the Modern Workplace
  • Security Experts Highlight Exploit for Patched Windows Flaw
  • Minecraft Users Warned of Malware Targeting Modpacks
  • Organizations Urged to Address Critical Vulnerabilities Found in First Half of 2023
  • Stealth Soldier: A New Custom Backdoor Targets North Africa with Espionage Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.