Known as Evil Extractor and developed by a company called Kodex as an “educational tool,” the attack tool is used by attackers to target Windows-based machines.
The claim comes from Fortinet security researchers and is explained in an advisory published Thursday.
“[We] Observed this malware in a phishing email campaign [disguised as account confirmation requests] Back on March 30th, the sample included in this blog. It usually masquerades as a legitimate file such as an Adobe PDF or Dropbox file, but once loaded, it begins leveraging PowerShell malicious activity,” the company wrote.
More information on phishing malware can be found here: DEV-1101 Updates Open Source Phishing Kit
Evil Extractor works through several modules that rely on the File Transfer Protocol (FTP) service.
Additionally, Evil Extractor includes environmental checks as well as anti-virtual machine (VM) and VirusTotal features designed to evade detection. This malware also has ransomware functionality called “Kodex Ransomware”.
“We recently investigated the version of malware injected into the victim’s system and as part of that analysis confirmed that most of the victims are located in Europe and the United States,” Fortinet explained. .
According to the advisory, the developer released the malware in October 2022 and continued to update it to improve stability and strengthen malicious functionality.
“EvilExtractor is used as a comprehensive information stealer with multiple malicious capabilities, including ransomware. Its PowerShell scripts can escape detection with .NET loaders or PyArmor,” says the tech. read relevant articles. “Users should be aware of this new information-stealing program and remain vigilant of suspicious emails.”
The advisory also includes indications of malware compromise, and comes weeks after Open Text cybersecurity experts warned against a significant spike in HTTPS phishing sites.