Dec 11, 2021
0 0

Malicious Notepad++ installers push StrongPity malware

Written by

New zero-day exploit for Log4j Java library is an enterprise nightmare
ALPHV BlackCat – This year’s most sophisticated ransomware
Volvo Cars discloses security breach leading to R&D data theft
Massive attack against 1.6 million WordPress sites underway
Researchers release ‘vaccine’ for critical Log4Shell vulnerability
The Week in Ransomware – December 10th 2021 – Project CODA
Phishing attacks use QR codes to steal banking credentials
Volvo Cars discloses security breach leading to R&D data theft
Qualys BrowserCheck
Junkware Removal Tool
How to remove the PBlock+ adware browser extension
Remove the Search Redirect
Remove the Search Redirect
Remove the Search Redirect
Remove Security Tool and SecurityTool (Uninstall Guide)
How to remove Antivirus 2009 (Uninstall Instructions)
How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo
How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller
Locky Ransomware Information, Help Guide, and FAQ
CryptoLocker Ransomware Information Guide and FAQ
CryptorBit and HowDecrypt Information Guide and FAQ
CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ
How to make the Start menu full screen in Windows 10
How to install the Microsoft Visual C++ 2015 Runtime
How to open an elevated PowerShell Admin prompt in Windows 10
How to Translate a Web Page in Google Chrome
How to start Windows in Safe Mode
How to remove a Trojan, Virus, Worm, or other Malware
How to show hidden files in Windows 7
How to see hidden files in Windows
IT Certification Courses
Gear + Gadgets
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware.
This hacking group, also known as APT-C-41 and Promethium, was previously seen distributing trojanized WinRAR installers in highly-targeted campaigns between 2016 and 2018, so this technique is not new.
The recent lure involves Notepad++, a very popular free text and source code editor for Windows used in a wide range of organizations.
The discovery of the tampered installer comes from a threat analyst known as ‘blackorbird’ analysts, while Minerva Labs reports on the malware.
#APT #StrongPity NotePad++ installer(npp.8.1.7.Installer.x64.exe)
Upon executing the Notepad++ installer, the file creates a folder named “Windows Data” under C:ProgramDataMicrosoft, and drops the following three files:
The installation of the code editor continues as expected, and the victim won’t see anything out of the ordinary that could raise suspicions.
As the setup finishes, a new service named “PickerSrv” is created, establishing the malware’s persistence via startup execution.
This service executes ‘ntuis32.exe’, which is the keylogger component of the malware, as an overlapped window (using WS_MINIMIZEBOX style).
The keylogger records all user keystrokes and saves them to hidden system files dumped created in the ‘C:ProgramDataMicrosoftWindowsData’ folder. The malware also has the ability to steal files and other data from the system.
This folder is continuously checked by ‘winpickr.exe,’ and when a new log file is detected, the component establishes a C2 connection to upload the stolen data to attackers.
Once the transfer has been completed, the original log is deleted to wipe the traces of malicious activity.
If you need to use Notepad++, make sure to source an installer from the project’s website
The software is available on numerous other websites, some of which claim to be the official Notepad++ portals but may include adware or other unwanted software.
The URL that was distributing the laced installer has been taken down following its identification by analysts, but the actors could quickly register a new one.
Follow the same precautions with all software tools you’re using, no matter how niche they are, as sophisticated actors are particularly interested in specialized software cases that are ideal for watering hole attacks.
In this case, the chances of detection from an AV tool on the system would be roughly 50%, so using up-to-date security tools is essential too.
QBot returns for a new wave of infections using Squirrelwaffle
New ‘Karakurt’ hacking group focuses on data theft and extortion
Emotet now drops Cobalt Strike, fast forwards ransomware attacks
Google disrupts massive Glupteba botnet, sues Russian operators
QNAP warns users of bitcoin miner targeting their NAS devices
Not a member yet? Register Now
New zero-day exploit for Log4j Java library is an enterprise nightmare
Massive attack against 1.6 million WordPress sites underway
To receive periodic updates and news from BleepingComputer, please use the form below.
Terms of Use Privacy PolicyEthics Statement
Copyright @ 2003 – 2021 Bleeping Computer® LLC – All Rights Reserved
Not a member yet? Register Now
Read our posting guidelinese to learn what content is prohibited.


Article Categories:
Cybersecurity News

Comments are closed.