Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
In this campaign we observed a PowerShell script being downloaded that installs a malicious Chromium-based browser extension that targets Google Chrome, Brave and Opera.
The command used for extraction is as follows: "C:\Users\???\AppData\Roaming\Viqwo Stars Ci\Rotq App\UnRar.exe" x -p3809610121t -o+ ...
The sample requires user interaction to execute, triggered by the execution of the setup.msi file.
The main purpose of the malware that is dropped by the Satacom downloader is to steal BTC from the victim’s account by performing web injections into targeted cryptocurrency websites. The malware attempts to do this by installing an extension for Chromium-based web browsers.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
The shellcode then proceed to start explorer.exe and use process hollowing to load the malicious stage 2 using CreateProcessInternalA, ZwQueryInformationProcess, ReadProcessMemory, ZtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory and NtResumeThread API calls.
Finally, the PS script recursively searches for any link (.LNK) file in the above locations and modifies the “Target” parameter for all existing browser shortcuts with the flag “–load-extension=[pathOfExtension]” so that the shortcut will load the browser with the malicious extension installed.
The shellcode then proceed to start explorer.exe and use process hollowing to load the malicious stage 2 using CreateProcessInternalA, ZwQueryInformationProcess, ReadProcessMemory, ZtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory and NtResumeThread API calls.
This buffer is then decoded, revealing the shellcode... Another buffer in then created and data is copied to it using the rep movsb instruction. This buffer is then decoded, revealing the stage 2 executable.
Since the malware later attempts to execute the payload using rundll32, it is highly likely that the final payload is a DLL...
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
For example, it can extract information through the browser, such as the system information, cookies, browser history, screenshots of opened tabs, and even receive commands from the C2 server.
For example, it has the ability to retrieve the victims’ addresses, obtain account information, bypass 2FA, and much more.
Within the MSI, two anti-sandbox mechanisms have been identified. The first anti-sandbox measure presents a button with the label “Please verify that you are not a robot.”. In one of the samples, it was observed that a virtual environment is detected through a feature of Advanced Installer.
JavaScripts: requesting commands from the C2 (left pane) and taking screenshots (right pane)
The malicious extension has various JS scripts to perform browser manipulations while the user is browsing the targeted websites, including enumeration and manipulation with cryptocurrency websites.
Stage 2 is responsible for communicating with the command and control (C2) server... the malware attempts to establish a connection to the C2 using WinHttpSendRequest.
To do so, it performs a DNS request to don-dns[.]com through Google DNS (8.8.8.8, another decrypted string) and it queries for the TXT record.
190 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader employing anti-analysis techniques.
A downloader malware family delivered via malicious or malvertising-driven websites that uses DNS TXT lookups to retrieve an encoded URL for next-stage payload delivery. In this campaign it ultimately installs a malicious Chromium-based browser extension that steals BTC, performs web injections against cryptocurrency sites, manipulates email services to hide fraudulent transactions, and communicates with C2 infrastructure whose address can be derived from Bitcoin transaction data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.