Story image

'URL file outbreak' used to distribute Quant Loader Trojan

11 Apr 2018

Barracuda Networks is tracking a potentially dangerous ‘URL file outbreak’ that distribute the Quant Loader Trojan, which in turn can distribute ransomware and password stealers.

Attackers are using a combination of phishing emails, social engineering, obfuscation, and a known exploit to distribute the Trojan.

According to Barracuda researchers, the threat seems to be distributed by emails disguised as billing documents, which started circulating last month. The emails contain attachments of zipped Microsoft internet shortcut files with a ‘.url’ file extension.

Researchers explain: “In the world of email, an unfamiliar file extension—especially one that is compressed alone in a ZIP file—is often a sure sign of a new malware outbreak.”

“These shortcut files use a variation on the CVE-2016-3353 proof-of-concept, containing links to JavaScript files (and more recently Windows Script Files). However, in this instance the URL was prefixed with "file://" rather than "http://" which fetches them over Samba rather than through a web browser.”

“This has the benefit of executing the contained code using WScript under the current user's profile rather than requiring browser exploitation, although it does prompt the user before doing so. The remote script files are heavily obfuscated, but all result in downloading and running Quant Loader when allowed to execute.”

Quant Loader is widely sold on underground forums and contains a management panel that allows attackers to configure any payloads they want to deliver. Researchers say configurable malware like this Trojan is becoming more common, separating malware development from distribution.

“The campaign itself has been composed of a number of mini-campaigns—each lasting for a less than a day. They are utilizing an email content and file name pattern (with some emails having no text content and only a subject line), a single domain serving malicious script files over Samba, and a single variant of Quant being distributed from a handful of domains,” they explain.

While the Samba shares are still active and publicly accessible, access is proving difficult.

“Attempting to access the URLs via HTTP has led to redirects at times, resulting in a random key generator file to be downloaded. Fortunately, these are generally flagged as malicious by most antivirus software. Based on the research we’ve done tracking this campaign—it isn’t showing up daily, but has shown up numerous times in March and April.”

Barracuda researchers say that users should avoid file types they are unfamiliar with, particularly when they are included in emails. “Certainly don't allow scripts to run that originated from files in email as well.”

Five things MSPs need to keep in mind in 2019
A Datto APAC channel exec outlines the most important factors for MSP to being paying attention to in the coming year.
Survey: IT pros nostalgic over on-prem data centre visibility
There are significant security and monitoring challenges faced by IT staff responsible for managing public and private cloud deployments.
61% of CIOs believe employees leak data maliciously
Egress conducted a survey to examine the root causes of employee-driven data breaches, their frequency, and impact.
Opinion: BYOD can be secure with the right measures
Companies that embrace BYOD are giving employees more freedom to work remotely, resulting in increased productivity, cost savings, and talent retention.
Sonatype and HackerOne partner on open source vulnerability reporting
Without a standard for responsible disclosure, even those who want to disclose vulnerabilities responsibly can get frustrated with the process.
OutSystems and Boncode team up for better code analysis
The Boncode and OutSystems alliance aims to help organisations to build fast and feel comfortable that the work they're delivering is at peak quality levels.
Security top priority for Filipinos when choosing a bank - Unisys
Filipinos have greatest appetite in Asia Pacific to use biometrics to access banking services
Nuance biometrics fight back against fraud
Nuance Communications has crunched the numbers and discovered that it has prevented more than US$1 billion worth of fraud from being passed on to users of its Nuance Security Suite.