Malware

New RedLine malware variant spread as fake Omicron stat counter

0

A new variant of the RedLine info-stealer is distributed via emails using a fake COVID-19 Omicron stat counter app as a lure.

RedLine is a widespread commodity malware sold to cyber-criminals. It provides dark web markets with over half of the stolen user credentials sold to other threat actors.

The malware is actively developed and continually improved with widespread deployment using multiple distribution methods.

RedLine targets user account credentials stored on the browser, VPN passwords, credit card details, cookies, IM content, FTP credentials, cryptocurrency wallet data, and system information.

Security analysts at Fortinet have discovered the most recent variant who noticed several new features and improvements on top of an already information-stealing functionality.

The new variant has new information points to exfiltrate, such as:

  • Graphics card name
  • BIOS manufacturer, identification code, serial number, release date, and version
  • Disk drive manufacturer, model, total heads, and signature
  • Processor (CPU) information like unique ID, processor ID, manufacturer, name, max clock speed, and motherboard information

This data is collected upon the first execution of the “Omicron Stats.exe” lure, which unpacks the malware and injects it into vbc.exe.

The other apps targeted by the new RedLine variant are the Opera GX web browser, OpenVPN, and ProtonVPN.

Previous versions of RedLine targeted regular Opera, but the GX is a special “gamer-focused” edition growing in popularity.

Also the malware now searches Telegram folders to locate images and conversation histories and send them back to the threat actor’s servers.

Finally, local Discord resources are inspected vigorously to discover and steal access tokens, logs, and database files.

Upon analyzing the new campaign, researchers found an IP address in Great Britain communicating with the command and control server via the Telegram messaging service.

The attack is not focused on specific organizations or individuals and the victims span across 12 countries.

As this is a new version of RedLine, it is likely that other threat actors might use it soon.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

New SysJoker spy malware targets Windows, macOS, and Linux users

Previous article

Firefox Focus now blocks cross-site tracking on Android devices

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *