Cyber Attacks

New Horabot campaign targets Gmail and Outlook accounts

0

A new cyber threat campaign involving the Horabot botnet malware has targeted Spanish-speaking users in Latin America since at least November 2020, infecting them with a banking trojan and spam tool.

Horabot is a documented PowerShell-based botnet that targets the victim’s Outlook mailboxes to steal contacts and disseminate phishing emails containing malicious HTML attachments.

The malware enables the hackers to take control of the victim’s Gmail, Outlook, Hotmail, or Yahoo email accounts, steal email data and 2FA codes arriving in the inbox, and send phishing emails from the compromised accounts.

The new Horabot operation which was discovered by analysts at Cisco Talos, are reported to be the work of threat actors based in Brazil.

The multi-stage infection chain begins with a tax-themed phishing email sent to the target, with an HTML attachment that is supposedly a payment receipt.

When the HTML is opened, it launches a URL redirection chain that takes the victim to an HTML page hosted on an attacker-controlled AWS instance.

The victim clicks on the hyperlink on the page and downloads a RAR archive that contains a batch file with a CMD extension, which downloads a PowerShell script that fetches trojan DLLs and a set of legitimate executables from the C2 server.

These trojans execute to fetch the final two payloads from a different C2 server. One is a PowerShell downloader script, and the other is the Horabot binary.

One of the DLL files in the downloaded ZIP is a banking trojan written in Delphi. It targets system info (language, disk size, antivirus software, hostname, OS version, IP address), user credentials, and activity data.

Moreover, the trojan also offers its operators remote access capabilities like performing file actions and can also conduct keylogging, screenshot snapping, and mouse event tracking.

When the victim opens an application, the trojan overlays a fake window on top of it to trick victims into entering sensitive data like online banking account credentials or one-time codes.

All information collected from the victim’s computer is sent to the attacker’s command and control server via HTTP POST requests.

The ZIP archive also contains an encrypted spam tool that can steal credentials for popular webmail services like Gmail, Hotmail, and Yahoo.

Once the credentials are compromised, the tool takes over the victim’s email account, generates spam emails, and sends them to the contacts found in the victim’s mailbox.

This tool also features keylogging, screenshot snapping, and mouse event interception or tracking capabilities, functionally overlapping with the banking trojan, possibly for redundancy.

Currently the Horabot campaign mainly targets users in Mexico, Uruguay, Brazil, Venezuela, Argentina, Guatemala, and Panama. The threat actors could expand its reach to other markets anytime by using phishing themes written in English.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

New Bandit Stealer targets web browsers and cryptocurrency wallets

Previous article

British Airways, BBC and Boots hit by Zellis data breach

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *