Side Loading through IObit against Colombia
Essential information
- Published
- 29/05/2024 11:06
- Modified
- 29/05/2024 11:30
- Tags
- 2024-05-29 asyncrat dllsideloading phishing processhollowing
- Related entities
- 3 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 1 others
Description
In May 2024, researchers detected a phishing campaign impersonating the Colombian Attorney General's Office, aiming to infect systems with AsyncRAT malware. The attack employs a ZIP file containing legitimate IObit antivirus software and malicious files, utilizing DLL side-loading for execution. While sharing similarities with APT-C-36, the kill-chain differs from their previous campaigns, suggesting modified tactics. The infection chain involves the legitimate IObit executable loading a malicious DLL, creating processes for code injection, and ultimately deploying AsyncRAT via process hollowing. Persistence mechanisms include a startup link file and scheduled task.