Hackers have been targeting online gaming and gambling companies with a new backdoor named IceBreaker since at least September 2022.
In the new attack campaign, the customer service agents were tricked into opening malicious screenshots which the hackers send under the guise of a user facing a problem.
The group behind the backdoor is not known yet although they have been observed using broken English during their conversations with customer service agents.
The researchers at incident response firm Security Joes believe that the IceBreaker backdoor is the work of a new advanced threat actor that uses “a very specific social engineering technique,” which could lead to a better picture of who they are.
After analyzing the data from an incident in September, Security Joes was able to respond to three other attacks before the hackers could compromise their targets.
The only public evidence of the IceBreaker threat actor the researchers could find was a tweet from MalwareHunterTeam in October.
In order to deliver the backdoor, the threat actor contacts the customer support of the target company pretending to be a user having problems logging in or registering for the online service.
The hackers convince the support agent to download an image that describes the problem better than they can explain. The image is hosted on a fake website that impersonates a legitimate service.
The links delivered this way lead to a ZIP archive containing malicious LNK file that fetches the IceBreaker backdoor, or a Visual Basic Script that downloads the Houdini RAT that’s been active since at least 2013.
According to the researchers, the downloaded malware is “a highly complex compiled JavaScript file” that can discover running processes, steal passwords, cookies, and files, open a proxy tunnel for the attacker, as well as run scripts retrieved from the attackers’ server.
The malicious LNK is the main first-stage payload delivering the IceBreaker malware, while the VBS file is used as a backup, in case the customer support operator is unable to run the shortcut.
The researchers have published a technical report describing the threat actor’s modus operandi and how their backdoor works. They recommend companies suspecting a breach with IceBreaker to look for shortcut files created in the startup folder and check for unauthorized execution of the open-source tool tsocks.exe.















Comments