Organizations in the Australian healthcare sector are targeted by hackers by using the Gootkit malware loader.
Trend Micro researchers analyzed a series of attacks and discovered that Gootkit leveraged SEO poisoning for its initial access and abused legitimate tools like VLC Media Player.
The SEO poisoning techniques targeting the Australian healthcare industry used keywords like “hospital”, “health”, “medical”, and “enterprise agreement”, paired with Australian city names. Threat actors also used healthcare providers across Australia.
According to a report published by Trend Micro, the abuse of VLC Media Player, a widely used legitimate tool, is another key feature of this attack. The malware authors sideloaded malicious DLL to abuse VLC Media Player and manipulated it as a part of Cobalt Strike.
VLC Media Player is one of the most popular software with over 3.5 billion downloads for Windows alone.
While searching for terms related to Australian healthcare industry, contaminated search results are proposed on the first page of search results.
Upon accessing the site, the user is taken to a screen that appears like a legitimate forum. When the users access the link, the malware-laced ZIP file can be downloaded.
The sites used to trick users into downloading malicious files due to SEO poisoning look like legitimate WordPress sites that have been compromised and abused.
Besides, the malicious JavaScript inserts its code into a legitimate JS file at random segments on the compromised websites.
A process launched from a scheduled task runs a PowerShell script and retrieves files for the attack chain from the C2 server that abused a legitimate WordPress site.
The second stage of infection takes place after the waiting time. During the waiting time, the scheduled task performed two C&C accesses per day, without executing any other process.
They added that this latency, which clearly separates the initial infection stage from the second stage, is a distinctive feature of Gootkit loader’s operation.
After the waiting time, the payloads are dropped (msdtc.exe and libvlc.dll). The msdtc.exe is a legitimate VLC Media Player that impersonates a legitimate Windows component, it loads libvlc.dll with its function as a module related to Cobalt Strike with the DLL sideloading technique.
Then the msdtc.exe acts as a part of Cobalt Strike while still being a valid signed and legitimate executable program.
On monitoring of Gootkit loader activity that uses SEO poisoning, it has been revealed that the threat actors behind it are actively implementing their campaign.
Image Credits : The 420













Comments