Threat Management, Malware

Trio of downloaders used in recent Blackmoon banking trojan campaign

Two recently observed cybertheft campaigns targeting South Koreans employed a three-stage downloader framework that installed the Blackmoon banking trojan on geo-targeted machines, according to a blog post Thursday from Fidelis Cybersecurity.

Taking place from late 2016 through 2017, the campaigns were aimed at users of such South Korean financial institutions as Samsung Pay, Citibank Korea, Hana Financial Group, KB Financial Group and more, Fidelis reports. Typically, Blackmoon is delivered in a variety of methods, including adware campaigns and exploit kits.

The three-stage delivery of Blackmoon, aka KRBanker or Banbra, was designed to help the cybercriminals evade detection, the blog post continues. The first component, an initial downloader, performs a GET request against a hardcoded URL, which sends bytecode in response. In turn, this bytecode second-stage downloader decodes data containing a URL that hosts the next file to be downloaded – a Portable Executable (PE) file that's named as a jpg. This file acts as a third-stage downloader, dubbed KRDownloaderwhich verifies that the user's default system language is Korean, connects to a command-and-control server, and introduces the main malicious payload. "When the user's language is not Korean, the bot simply dies," the blog post explains.

The campaigns no longer appear active, confirmed John Bambenek, Fidelis's manager of threat intelligence systems, in an email exchange with SC Media.

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.