216.73.216.6

Pirated Business Software Activator Spreads RedLine Stealer

· Published 10/12/2024 13:42 · Modified 10/12/2024 14:03

Export JSON

Essential information

Published
10/12/2024 13:42
Modified
10/12/2024 14:03
Tags
2024-12-10 redline stealer
Related entities
12 observables, 10 techniques (mitre), 1 malware, 1 others

Description

A malicious campaign targeting users of unlicensed corporate business automation software has been discovered. The attackers are distributing malicious activators on accounting forums that contain the hidden in an unusual way. The activator library is obfuscated using .NET Reactor, with the malicious code compressed and encrypted in multiple layers. The campaign began in January 2024 and continues to threaten users of unlicensed software. The attackers aim at entrepreneurs using current versions of a business process automation platform, spreading their solution disguised as a new version of the HPDxLIB activator. The malicious version differs from the 'clean' one primarily by using .NET and having a new self-signed certificate.

External references