Dridex Malware Takes The Piss (Or So It Claims)

Researchers from cybersecurity firm Proofpoint have been tracking a new Dridex malware campaign, which is targeting UK users via invoice emails claiming to be from a portable toilet company.

The Dridex campaign has some unusual features (as well as the millions of messages, which have become the new normal for these very large Dridex campaigns).

Dumps

The campaign combines three different methods for dumping its payload in an attempt to increase its effectiveness.

The final payload is Dridex botnet ID 220 and this campaign is targeting the UK users (with injects for UK, AU and FR banks). While the targeting and botnet are nothing new, the combined vectors are.

The messages sent in this campaign include:

– Both Microsoft Word and Excel attachments with malicious macros

– Document-based exploits that automatically download Dridex when the documents are opened on vulnerable systems (CVE-2015-1641 and possibly CVE-2012-0158)

– Zipped JavaScript attachments disguised as PDF documents. This is a new approach for Dridex, although the JavaScript functions identically to the documents, attempting to download Dridex when executed by user.

Only one vector occurs in each email, so the actors rotated among them throughout the campaign.

A Proofpoint researcher said: “The invoice itself claims to be for portable toilet rental. While some users may immediately discard this as spam – how many of us rent portable toilets regularly? – others may open the documents out of sheer curiosity.”

The key takeaways here are:

– Dridex actors are getting creative in the vectors they use to deliver their payloads and are exploring new means for hiding from antivirus software and other detection measures

– Curiosity can, in fact, kill the cat – It is always worth reminding users not to open unusual or suspect attachments.

Take our hackers and viruses quiz!

Duncan Macrae

Duncan MacRae is former editor and now a contributor to TechWeekEurope. He previously edited Computer Business Review's print/digital magazines and CBR Online, as well as Arabian Computer News in the UAE.

Recent Posts

WhatsApp Appeal Against EU Fine Backed By Court Advisor

Notable development for Meta, after appeal against 2021 WhatsApp privacy fine is backed by advisor…

13 hours ago

Intel Board Shakeup As Three Members Confirm Retirement

First sign of shakeup under new CEO Lip-Bu Tan? Three Intel board members confirm they…

14 hours ago

Trump’s SEC Pick Pledges ‘Coherent’ Crypto Rules

Trump's nominee for SEC Chairman, Paul Atkins, has pledged a “rational, coherent, and principled approach”…

14 hours ago

Former Intel CEO Pat Gelsinger Joins Venture Capital Firm

After being 'retired' by Intel's board of directors, ex-CEO Pat Gelsinger has joined a VC…

19 hours ago

Trump Says China Tariffs May Be Cut To Seal TikTok Deal

President touts easing Chinese tariffs to facilitate TikTok sale, and also implements 25 percent tariff…

21 hours ago

Newspaper Lawsuit Against OpenAI Can Proceed Says Judge

Copyright lawsuit against OpenAI and Microsoft from The New York Times and other newspapers can…

22 hours ago