{"id":16966,"date":"2023-02-08T13:33:08","date_gmt":"2023-02-08T12:33:08","guid":{"rendered":"https:\/\/www.show.it\/a-deep-dive-into-the-growing-gootloader-threat\/"},"modified":"2023-02-08T13:33:08","modified_gmt":"2023-02-08T12:33:08","slug":"a-deep-dive-into-the-growing-gootloader-threat","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/a-deep-dive-into-the-growing-gootloader-threat\/","title":{"rendered":"A Deep Dive Into the Growing GootLoader Threat"},"content":{"rendered":"<p>GootLoader was born from GootKit, a banking trojan that first appeared around 2014. In recent years GootKit has evolved into a sophisticated and evasive loader \u2014 and it was given a new name to reflect its new purpose in 2021. The same group is responsible for both versions of the malware, and is monitored by Mandiant as UNC2565.<\/p>\n<p>The evolution of GootLoader reflects the evolution of cybercriminal gangs. Many of the more sophisticated gangs are switching to a malware-as-a-service business model. They develop the malware, but less-advanced gangs or individuals pay for use of that malware. In this case, it is access (or victim) as a service. GootLoader provides access to victims primarily for ransomware. The access is likely taken up by ransomware-as-a-service (RaaS) groups who sell-on the access to ransomware groups or individual criminals. For further details on this business model, see Cyber Insights 2023: <a href=\"https:\/\/www.securityweek.com\/cyber-insights-2023-criminal-gangs\/\">Criminal Gangs<\/a>.<\/p>\n<p>GootLoader continues to evolve. Researchers at Cybereason have published a <a href=\"https:\/\/www.cybereason.com\/blog\/threat-alert-gootloader-seo-poisoning-and-large-payloads-leading-to-compromise\" target=\"_blank\" rel=\"noreferrer noopener\">deep dive<\/a> into the latest version.\u00a0<\/p>\n<p>The infection journey starts within compromised WordPress sites. These sites are given greater validity through SEO poisoning techniques, with key words likely hidden within html code on valid pages. Google Ads may also be used. With a high search engine ranking, potential victims are more likely to visit the compromised site.<\/p>\n<p>The primary targets are healthcare and finance within English speaking countries, such as the US, the UK and Australia.<\/p>\n<p>If a victim is drawn into a watering hole WordPress site, he is provided with a ZIP file containing a malicious JavaScript. This is described as stage-1 of the GootLoader infection. The JavaScript establishes persistence by creating and running a \u2018Customer Engineering\u2019 scheduled task. It also generates a second JavaScript file (stage-2 of the infection) which is 40 MB in size (random junk code is added, probably to confuse and evade detection).<\/p>\n<p>The Customer Engineering task has been configured to execute this large new JavaScript file. It ultimately provides PowerShell code, which executes a command and control function every 20 seconds using random GootLoader C2 URLs as parameters. It uses system discovery calls to obtain the environment variables, processes, desktop items and disks on the victim machine. This data is compressed, and encoded, and sent to the C2 disguised as a cookie.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/www.securityweek.com\/wp-content\/uploads\/2023\/02\/GootLoader-infection-process-1024x943.png\" alt=\"\" class=\"wp-image-32443\" width=\"506\" height=\"466\" srcset=\"https:\/\/www.securityweek.com\/wp-content\/uploads\/2023\/02\/GootLoader-infection-process-1024x943.png 1024w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2023\/02\/GootLoader-infection-process-360x332.png 360w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2023\/02\/GootLoader-infection-process-768x707.png 768w, https:\/\/www.securityweek.com\/wp-content\/uploads\/2023\/02\/GootLoader-infection-process.png 1200w\" sizes=\"(max-width: 506px) 100vw, 506px\"><figcaption class=\"wp-element-caption\"><em>\u00a0GootLoader infection process<\/em> (Image Credit: Cybereason IR team)<br \/><\/figcaption><\/figure>\n<\/div>\n<p>As an aside, the researchers used <a href=\"https:\/\/www.securityweek.com\/malicious-prompt-engineering-with-chatgpt\/\">ChatGPT<\/a> to make some of the PowerShell code more easily understood. It was used, for example, to change the original variable names into more descriptively pertinent names. This it did effectively, but researcher Loic Castel told <em>SecurityWeek<\/em> that ChatGPT\u2019s value to seasoned researchers is limited. \u201cIt cannot help with the more complex work \u2013 couldn\u2019t help with the de-obfuscation \u2013 but it may be used by junior researchers in more basic stages.\u201d<\/p>\n<p>Lateral movement starts with disabling Microsoft Defender, and proceeds with Cobalt Strike loaded through DLL hijacking. SystemBC is deployed.<\/p>\n<p>Cybereason was unable to see the final effect of GootLoader. The instance comes from its own telemetry where it detected and stopped GootLoader\u2019s progress. The final malware deployment didn\u2019t happen. But they did detect the deployment of SystemBC.\u00a0<\/p>\n<p>\u201cSystemBC is what we call the precursor of ransomware,\u201d explained Castel. \u201cWe often see it hours, maybe days, before the ransomware is actually deployed. This is something that is often deployed just before a ransomware attack.\u201d<\/p>\n<p>Any subsequent ransomware attack would almost certainly not have been delivered by UNC2565. Their function within the modern criminal ecosphere is to provide access to victims, and to sell that access to other criminals. The final payload is not pre-defined, but it seems likely to be particularly relevant for ransomware.<\/p>\n<p>GootLoader is not a specifically targeted attack. However, some generalized targeting is achieved through the development of the original watering hole process. This suggests that this instance of the malware is aimed at the healthcare and finance sectors within English-speaking countries.<\/p>\n<p>Cybereason assesses the GootLoader threat level as \u2018severe\u2019. The malware uses a combination of evasion and living off the land techniques, and its presence is unlikely to be spotted by anything other than AI-assisted anomaly detection.<\/p>\n<p><strong>Related<\/strong>: <a href=\"https:\/\/www.securityweek.com\/ransomware-malware-service-dominate-threat-landscape\/\">Ransomware, Malware-as-a-Service Dominate Threat Landscape<\/a><\/p>\n<p><strong>Related<\/strong>: <a href=\"https:\/\/www.securityweek.com\/recent-gootloader-campaign-targets-law-accounting-firms\/\">Recent GootLoader Campaign Targets Law, Accounting Firms<\/a><\/p>\n<p><strong>Related<\/strong>: <a href=\"https:\/\/www.securityweek.com\/mouseover-macro-campaign-delivers-gootkit-trojan-powerpoint\/\">Mouseover Macro Campaign Delivers Gootkit Trojan Via PowerPoint<\/a><\/p>\n<p><strong>Related<\/strong>: <a href=\"https:\/\/www.securityweek.com\/gootkit-trojan-targets-banks-redirection-attacks\/\">GootKit Trojan Targets Banks With Redirection Attacks<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/a-deep-dive-into-the-growing-gootloader-threat\/\">A Deep Dive Into the Growing GootLoader Threat<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/\">SecurityWeek<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GootLoader was born from GootKit, a banking trojan that first appeared around 2014. In recent years GootKit has evolved into a sophisticated and evasive loader \u2014 and it was given a new name to reflect its new purpose in 2021. The same group is responsible for both versions of the malware, and is monitored by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16967,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[202,203,80,204],"tags":[],"class_list":["post-16966","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gootkit","category-gootloader","category-malware-threats","category-unc2565"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16966","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=16966"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16966\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/16967"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=16966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=16966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=16966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}