Categories: Cyber CrimeSecurity

Uncovered an unusual attacks based on anomalous file infector

Security experts uncovered an unusual cyber espionage campaign based on file infector belonging to the PE_EXPIRO family that includes information theft module

Security experts at TrendMicro uncovered an unusual espionage campaign that hit United States users based  on malware having file infector with stealing capabilities. The attackers acted with specific intent to steal information from organizations or to compromise websites targeting of FTP credentials. The researchers estimated that nearly 70% of total infections hit United States users, this circumstance led them to believe that the attack was intended to steal information from US organizations.

Unfortunately it’s not surprising that a security firm uncover a targeted attack, in the last weeks TrendMicro already alerted the security community on an ongoing targeted attack against  Asian and European government agencies, meanwhile the same security firm last month revealed another cyber espionage campaign dubbed Naikon that used RARSTONE malware for the related spear-phishing attacks.

The Naikon campaign hit companies across Asia (e.g. India, Malaysia, Singapore, and Vietnam) belonging to different sectors such as telecommunications, energy, governments, media, and others.

The anomaly resides in the file infector that is equipped with a routine designed to steal data from victim’s systems. The researchers at TrendMicro revealed that the cyber threat has been spotted with an unexpected combination exploit kits, mainly Java and PDF exploits, to deliver file infectors.

The malicious code of file infector belongs to the PE_EXPIRO family spread on into the wild since 2010, but the new variant also includes information theft module.

The blog post describes the infection chain as composed by following steps:

  • The user is lured to a malicious site which contains an exploit kit. Several exploits are used; one of these is a Java exploit (detected as JAVA_EXPLOIT.ZC) which uses CVE-2012-1723. Another Java vulnerability (CVE-2013-1493) is also being used. A PDF exploit is also being used, with the malicious PDF file detected as TROJ_PIDIEF.JXM.
  • Whatever exploit is used, the end result is the same: the mother file infector (either PE_EXPIRO.JX-O, PE_EXPIRO.QW-O, or PE64-EXPIRO-O for 64-bit systems) onto the affected system.
  • Once on the affected system, it seeks out .EXE files in the system to infect. All folders in all available drives (removable, shared, networked) are subjected to this search. The infected files are detected as PE_EXPIRO.JX.
  • It steals system and user information, such as the Windows product ID, drive volume serial number, Windows version and user login credentials. It also steals stored FTP credentials from the Filezilla FTP client.
  • The stolen information is then saved in a .DLL file and uploaded to various command-and-control (C&C) servers.

 

As usual the best way to protect the systems it is strongly suggested to deploy proper defense mechanisms and keep the entire architecture updated.

Pierluigi Paganini

(Security Affairs – Malware, file infector, cyberespionage)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Mozilla fixed zero-days recently demonstrated at Pwn2Own Berlin 2025

Mozilla addressed two critical Firefox vulnerabilities that could be potentially exploited to access sensitive data…

34 minutes ago

Japan passed a law allowing preemptive offensive cyber actions<gwmw style="display:none;"></gwmw>

Japan passed a law allowing preemptive offensive cyber actions, shifting from its pacifist stance to…

6 hours ago

Pwn2Own Berlin 2025: total prize money reached $1,078,750

Pwn2Own Berlin 2025 wrapped up with $383,750 awarded on the final day, pushing the total…

11 hours ago

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 45

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

1 day ago

Security Affairs newsletter Round 524 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles…

1 day ago