July 9, 2019 By David Bisson 2 min read

Security researchers observed the TA505 threat group delivering two new payloads, the Gelup malware tool and the FlowerPippi backdoor, via spam campaigns.

Trend Micro detected the spam campaign on June 20 targeting users in Japan, the Philippines and Argentina. The attackers crafted their emails to deliver DOC and XLS files containing malicious Visual Basic for Applications (VBA) macros. These scripts, in turn, downloaded FlowerPippi malware, which functioned as a backdoor on infected machines.

That’s not all Trend Micro found. In their analysis of FlowerPippi, the researchers discovered that the spam campaign pushed out another new malware tool called Gelup. Written in C++ and designed to function as a downloader of other malware, Gelup stood out for its obfuscation techniques. Gelup can also bypass User Account Control (UAC) by mocking trusted directories, abusing auto-elevated executables and using the Dynamic Link Library (DLL) side-loading technique.

A Busy Year for the TA505 Threat Group

Gelup — detected by Proofpoint as AndroMut — and FlowerPippi are just some of TA505’s latest innovations. In January, Proofpoint observed the threat group using two new malware tools — the ServHelper backdoor and the FlawedGrace remote access Trojan (RAT) — to target banks, retail businesses and restaurants.

Just a few months later, Cybereason detected a campaign launched by the group that used living-off-the-land binaries (LOLBins) and legitimate Windows operating system (OS) processes to deliver ServHelper.

Around that same time, Trend Micro discovered a campaign in which the threat actor targeted users in Chile and Mexico with samples of the FlawedAmmyy RAT and RMS RAT malware families.

Embrace a Layered Approach to Spam Detection

To help defend against TA505 and its ever-expanding arsenal of malware, start by creating a layered approach to email security that consists of mail scanning, antispam filters and security awareness training. Security teams should also use ahead-of-threat detection to block potentially malicious domains before they become active in phishing attacks and other campaigns.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today