• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new dotrunpex malware delivers multiple malware families via malicious ads

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

You are here: Home / General Cyber Security News / New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads
March 20, 2023

A new piece of malware dubbed dotRunpeX is being applied to distribute many identified malware family members this sort of as Agent Tesla, Ave Maria, BitRAT, FormBook, LokiBot, NetWire, Raccoon Stealer, RedLine Stealer, Remcos, Rhadamanthys, and Vidar.

“DotRunpeX is a new injector composed in .NET utilizing the System Hollowing procedure and applied to infect techniques with a range of recognised malware people,” Check Place said in a report published very last week.

Explained to be in active progress, dotRunpeX arrives as a second-stage malware in the an infection chain, usually deployed by using a downloader (aka loader) which is transmitted as a result of phishing e-mails as malicious attachments.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Alternatively, it is regarded to leverage destructive Google Ads on search result webpages to direct unsuspecting consumers exploring for well-known software package these types of as AnyDesk and LastPass to copycat internet sites hosting trojanized installers.

The most up-to-date DotRunpeX artifacts, initially noticed in October 2022, incorporate an additional obfuscation layer by working with the KoiVM virtualizing protector.

DotRunpeX Malware

It truly is really worth pointing out that the findings dovetail with a malvertising campaign documented by SentinelOne very last month in which the loader and the injector factors were collectively referred to as MalVirt.

Test Point’s evaluation has even further unveiled that “every dotRunpeX sample has an embedded payload of a certain malware spouse and children to be injected,” with the injector specifying a checklist of anti-malware procedures to be terminated.

WEBINARDiscover the Concealed Dangers of Third-Party SaaS Apps

Are you conscious of the dangers affiliated with 3rd-party application entry to your company’s SaaS applications? Sign up for our webinar to master about the styles of permissions getting granted and how to reduce risk.

RESERVE YOUR SEAT

This, in switch, is created probable by abusing a susceptible procedure explorer driver (procexp.sys) that’s included into dotRunpeX so as to attain kernel method execution.

There are signals that dotRunpeX could be affiliated to Russian-talking actors centered on the language references in the code. The most usually sent malware families shipped by the emerging risk incorporate RedLine, Raccoon, Vidar, Agent Tesla, and FormBook.

Found this write-up interesting? Stick to us on Twitter  and LinkedIn to read through extra exclusive content material we submit.


Some elements of this article are sourced from:
thehackernews.com

Previous Post: «mispadu banking trojan targets latin america: 90,000+ credentials stolen Mispadu Banking Trojan Targets Latin America: 90,000+ Credentials Stolen
Next Post: BreachForums Admin Arrested in New York Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.