Security researchers have discovered a new global campaign that relies on infostealers targeting Facebook and YouTube accounts.
Called “S1ideload Stealer” by bit defendernew malicious software employs DLL sideloading techniques to execute malicious components.
Bitdefender security researcher Dávid ÁCS writes: Recommendation Published on Wednesday. “S1deload Stealer effectively infects systems as it helps sideloading to bypass system defenses.”
Additionally, the executable also relies on the actual image folder, reducing user suspicion of malware.
After initial infection, S1deload Stealer not only obtains user credentials, but can mimic human behavior to artificially increase engagement with videos and other content.
It is also reportedly capable of assessing the system worth of individual accounts, mining BEAM cryptocurrency, and spreading malicious links to users’ followers.
“While this may look like a personal credential exposure, some of the credentials stolen by such attacks are corporate email credentials used for BEC attacks. ‘ explained. Roller Co-founder Drol River.
“With users using the same device for both personal and work, the line between personal and corporate credentials is blurred and gone,” he added.
More generally, Roger Grimes is an evangelist for data-driven defense. KnowBe4explained that malware like S1deload Stealer always find ways to mitigate it.
“What we do is track down and try to defeat individual threats when we need to focus on the root causes of successful exploitation,” Grimes said. It’s just playing a losing game of slaps.” Information security on mail.
“This and most malware can be prevented by actively training ourselves and our users on how to spot and defeat social engineering attacks,” added Grimes.
More information on the S1deload Stealer is available in our recent article. white paper By the Bitdefender team.
The analysis comes weeks after Symantec researchers alerted system defenders. another infostealer It’s called Graphyron and targets Ukraine.
Image credit: I AM NIKOM / Shutterstock.com