• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new dotrunpex malware delivers multiple malware families via malicious ads

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

You are here: Home / General Cyber Security News / New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads
March 20, 2023

A new piece of malware dubbed dotRunpeX is being applied to distribute many identified malware family members this sort of as Agent Tesla, Ave Maria, BitRAT, FormBook, LokiBot, NetWire, Raccoon Stealer, RedLine Stealer, Remcos, Rhadamanthys, and Vidar.

“DotRunpeX is a new injector composed in .NET utilizing the System Hollowing procedure and applied to infect techniques with a range of recognised malware people,” Check Place said in a report published very last week.

Explained to be in active progress, dotRunpeX arrives as a second-stage malware in the an infection chain, usually deployed by using a downloader (aka loader) which is transmitted as a result of phishing e-mails as malicious attachments.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Alternatively, it is regarded to leverage destructive Google Ads on search result webpages to direct unsuspecting consumers exploring for well-known software package these types of as AnyDesk and LastPass to copycat internet sites hosting trojanized installers.

The most up-to-date DotRunpeX artifacts, initially noticed in October 2022, incorporate an additional obfuscation layer by working with the KoiVM virtualizing protector.

DotRunpeX Malware

It truly is really worth pointing out that the findings dovetail with a malvertising campaign documented by SentinelOne very last month in which the loader and the injector factors were collectively referred to as MalVirt.

Test Point’s evaluation has even further unveiled that “every dotRunpeX sample has an embedded payload of a certain malware spouse and children to be injected,” with the injector specifying a checklist of anti-malware procedures to be terminated.

WEBINARDiscover the Concealed Dangers of Third-Party SaaS Apps

Are you conscious of the dangers affiliated with 3rd-party application entry to your company’s SaaS applications? Sign up for our webinar to master about the styles of permissions getting granted and how to reduce risk.

RESERVE YOUR SEAT

This, in switch, is created probable by abusing a susceptible procedure explorer driver (procexp.sys) that’s included into dotRunpeX so as to attain kernel method execution.

There are signals that dotRunpeX could be affiliated to Russian-talking actors centered on the language references in the code. The most usually sent malware families shipped by the emerging risk incorporate RedLine, Raccoon, Vidar, Agent Tesla, and FormBook.

Found this write-up interesting? Stick to us on Twitter  and LinkedIn to read through extra exclusive content material we submit.


Some elements of this article are sourced from:
thehackernews.com

Previous Post: «mispadu banking trojan targets latin america: 90,000+ credentials stolen Mispadu Banking Trojan Targets Latin America: 90,000+ Credentials Stolen
Next Post: BreachForums Admin Arrested in New York Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Enzo Biochem Hit by Ransomware, 2.5 Million Patients’ Data Compromised
  • US and Korean Agencies Issue Warning on North Korean Cyber-Attacks
  • Malicious PyPI Packages Use Compiled Python Code to Bypass Detection
  • New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America
  • The Importance of Managing Your Data Security Posture
  • Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering
  • Insurers Predict $33bn Bill for Catastrophic “Cyber Event”
  • Chinese Phishing Gang “PostalFurious” Expands Campaign
  • Kaspersky Says it is Being Targeted By Zero-Click Exploits
  • North Korea’s Kimsuky Group Mimics Key Figures in Targeted Cyber Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.