Malware

New BunnyLoader, a feature-rich malware-as-a-service threat emerges

0

Security researchers discovered a new malware-as-a-service (MaaS) called ‘BunnyLoader’ which has been advertised on multiple hacker forums as a fileless loader that can steal and replace the contents of the system clipboard.

The malware which is under rapid development, has updates adding new features and bug fixes. It can currently download and execute payloads, log keys, steal sensitive data and cryptocurrency, and execute remote commands.

The first version of BunnyLoader emerged on September 4. Since then, new functions were added to it such as multiple anti-detection mechanisms and extra info-stealing capabilities and a second major version was released towards the end of the month.

According to the researchers at cloud security company Zscaler, the BunnyLoader is quickly becoming popular among cybercriminals as a feature-rich malware available for a low price.

BunnyLoader’s command and control panel allows even low-skilled cybercriminals set a second-stage payload, enable keylogging, credential stealing, clipboard manipulation (for stealing cryptocurrency), and running remote commands on infected devices.

After being executed on a compromised device, BunnyLoader creates a new value in the Windows Registry for persistence, hides its window, sets a mutex to avoid multiple instances of itself, and registers the victim into the control panel.

The malware performs several checks to determine if it’s running on a sandbox or simulated environment and throws a fake architecture incompatibility error if the result is positive.

The malware also has other features such as modules to steal data stored on web browsers (passwords, credit cards, browsing history), cryptocurrency wallets, VPNs, messaging apps, and more, essentially acting as a standard info-stealer.

All stolen data are compressed into a ZIP archive before they are exfiltrated to the threat actor’s command and control (C2) server.

BunnyLoader supports writing payloads to the disk before executing them, and can also run them from the system memory using the process hollowing technique.

In its current state, BunnyLoader is sold for $250, while the “private stub” version, which features stronger anti-analysis, in-memory injection, AV evasion, and additional persistence mechanisms, is sold for $350.

This low price, combined with the rapid development cycle, make BunnyLoader a best choice for cybercriminals.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Microsoft’s Bing chat faces malware threat from deceptive ads

Previous article

Flagstar Bank suffered another data breach

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *