March 3, 2020 By David Bisson 2 min read

Security researchers discovered a new malvertising campaign launched by the Domen social engineering toolkit.

On February 19, Malwarebytes discovered a new malvertising campaign leveraging a VPN service as a lure. The campaign featured a host of domains that were new to Domen’s attack infrastructure. These included search-one[.]info as its fraudulent page, mix-world[.]best as its download site and panel-admin[.]best as its backend panel.

Ultimately, the campaign leveraged a series of redirects to expose users to Smoke Loader. In one attack instance detected by Malwarebytes’ researchers, this malicious downloader installed numerous secondary payloads. Those payloads included the IntelRapid cryptominer, a Vidar stealer and Buran ransomware.

This wasn’t the first campaign to feature some of those payloads together. For instance, Cybereason discovered an attack campaign that drew from various accounts in Bitbucket, a code repository platform, to load IntelRapid and Vidar along with the AZORult Trojan, STOP ransomware and other payloads.

A Look Back at Domen’s Recent Activity

Malwarebytes first reported on Domen’s malvertising activity in September 2019. At the time of its analysis, the security firm observed the social engineering toolkit using compromised websites to trick visitors into clicking on a fake Adobe Flash Player update. Clicking on the “Update” button caused the campaign to download “download.hta.” This script then used PowerShell to connect to xyxyxyxyxy[.]xyz and download the NetSupport remote-access Trojan (RAT) as its malware payload.

Even so, Domen didn’t first awaken in the fall of 2019. Malwarebytes confirmed this when it found an ad for the toolkit that malicious actors had posted on a black hat forum back in April of that year.

How to Defend Against a Malvertising Campaign

Security professionals can help their organizations defend against malvertising campaigns by staying on top of patch management. While not evident in the Domen operations described above, many other malvertising campaigns commonly use exploit kits as a means of distributing their malware payloads. Additionally, infosec personnel should invest in a unified endpoint management (UEM) solution to grant visibility into all their endpoints. Doing so will help teams quickly detect and remediate an infection from an attack campaign’s malware payload.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today