216.73.216.233

Side Loading through IObit against Colombia

· Published 29/05/2024 11:06 · Modified 29/05/2024 11:30

Export JSON

Essential information

Published
29/05/2024 11:06
Modified
29/05/2024 11:30
Tags
2024-05-29 asyncrat dllsideloading phishing processhollowing
Related entities
3 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 1 others

Description

In May 2024, researchers detected a campaign impersonating the Colombian Attorney General's Office, aiming to infect systems with malware. The attack employs a ZIP file containing legitimate IObit antivirus software and malicious files, utilizing DLL side-loading for execution. While sharing similarities with APT-C-36, the kill-chain differs from their previous campaigns, suggesting modified tactics. The infection chain involves the legitimate IObit executable loading a malicious DLL, creating processes for code injection, and ultimately deploying via process hollowing. Persistence mechanisms include a startup link file and scheduled task.

External references