HomeTechnologyNASA: Hackers Hiding Malware...

NASA: Hackers Hiding Malware in James Webb Telescope Images

A cybersecurity firm has uncovered a campaign that uses an image captured by the James Webb Telescope to distribute malware to users. | Font: NASA/Unsplash

adUnits.push({
code: ‘Rpp_tecnologia_mas_tecnologia_Nota_Interna1’,
mediaTypes: {
banner: {
sizes: (navigator.userAgent.match(/iPhone|android|iPod/i)) ? [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100]] : [[300, 250], [320, 460], [320, 480], [320, 50], [300, 100], [320, 100], [635, 90]]
}
},
bids: [{
bidder: ‘appnexus’,
params: {
placementId: ‘14149971’
}
},{
bidder: ‘rubicon’,
params: {
accountId: ‘19264’,
siteId: ‘314342’,
zoneId: ‘1604128’
}
},{
bidder: ‘amx’,
params: {
tagId: ‘MTUybWVkaWEuY29t’
}
},{
bidder: ‘oftmedia’,
params: {
placementId: navigator.userAgent.match(/iPhone|android|iPod/i) ? ‘22617692’: ‘22617693’
}
}]
});

James Webb and the high-resolution images of the universe it captures have become a new means by which cybercriminals they scam and distribute malware to their potential victims. through the campaign “GO#WEBBFUSCTOR” based on letters from phishingmalicious files and the aforementioned space images, hackers began to distribute computer viruses to various users.

According to the firm’s report securonicsthe domains for the campaign were registered on May 29, 2022 and the malware is written in golanga programming language that has become popular among hackers because it is cross-platform, that is, it works with Windows, Linux D Poppy. In addition, it provides increased resistance to reverse engineering and analysis by cybersecurity experts.

From what is stated in the report, it is known that the author of this threat sends payloads that are not marked as malicious by the engines. antivirus scanning platform VirusTotal.

James Webb Image Infection Chain

The firm’s report mentions that the infection begins with a phishing email with a malicious attachment named “Geos-Rates.docx” which is loaded into the template. This file contains a VBS macro that runs automatically if Office macros are enabled. Then this code loads a JPG image named “OxB36F8GEEC634.jpg” remote resource xmlschemeformat[.]com” decode it into an executable using certutil.exe to run it.

With the image viewer you can see JPG file shows a cluster of galaxies SMAX 0723photographed with the James Webb Telescope POT in July 2022. While at first glance it appears to be a harmless copy of this photo, opening it in a text editor reveals that the image contains additional information disguised as the attached certificate. This is a payload encoded in Base64 which is then converted into a malicious 64-bit executable.

NASA James Webb Virus
On the left is an image taken by James Webb, and on the right is the code hiding the malware in the JPG file. | Font: securonics

What is hidden malware doing in James Webb’s images?

Based on the results of dynamic analysis, malware ensures its permanence in the command by copying itself to the address “%%localappdata%%microsoftvault” from the storage unit and adding a new registry key. Once launched on the system, the malware establishes a DNS connection with command and control server (C2) to send encrypted requests.

Encrypted messages are read and decrypted in C2 serverthus revealing its original content.points out Securonix and further mentions that C2 can respond to malware by setting time intervals between connection requests, changing the nslookup timeout, or sending commands to be executed using the cmd.exe tool. Window.

In the course of tests conducted by the firm, it was found that the authors of this cyber threat they ran arbitrary numbering commands on their test systems, which was the first step towards standard recognition.

We recommend you METADATA, an RPP tech podcast. News, analytics, reviews, recommendations and everything you need to know about the world of technology. To hear better, #StayHome.

Source: RPP

- A word from our sponsors -

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

- A word from our sponsors -

Read Now

Russian informant prepared a missile blow to Maria Harkova (photo)

Counterintelligence SBU detained a Russian informant who prepared the enemy’s missile attack on the Harkiva City Hall. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } The press center of the...

Rossi Dron hit two Ski cars in the Harkov region (photo)

Yesterday, July 16, in the area of Korunsk yesterday, Russian invaders attacked the FPV-A-Mronus ambulance. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } Two health workers were damaged by the...

64 from the brine was attacked by Ukraine on the night of July 17 (infographics)

Russian invaders on the night of July 17 (from July 20, 16) attacked Ukraine of a total of 64 unmanned aerial vehicles and imitators of various types. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action:...

Zelensky’s contribution to the Council of the Council on the appointment of Sviridenko (document)

Volodymyr Zelensky, the President of Ukraine, presented to Verkhovna Radov’s submission to the appointment of Yulia Sviridenko for the position of prime minister -minister. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } ...

Rosie hired is gaining a war against Ukraine in the new scheme – SAS

In Russia, a new scheme for sending mercenaries to the war against Ukraine was launched - through the system of a doorsture or volunteer corps. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } ...

Zelensky represented the “servants” a new composition of the Cabinet of Ministers (list)

There was a meeting of the “Servant of People” faction, which was attended by the President of Ukraine Volodymyr Zelenski, Presidential Head Andrie Yermak, Verkhovna Chairman Ruslan Stefanchuk and First Vice Speaker Alexander Kornienko. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22...

Will make an insert and holds the country – part five years of the government

Former Prime Minister Denis Schmigal, who resigned today, on July 16, published a message in his telegram, in which for five years he thanked the Cabinet of Ministers to the Cabinet of Ministers. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width:...

The Council rushed to the faces for 60 years served in APU

During his meeting today, July 16, the Verkhovna Rada adopted as a whole bill No. 13229 on amendments to the Law on Military Service and Military Service under a military service contract under an agreement of persons who have reached the age of...

Izrail strikes the General Staff of the Syrian Army in Damascus (video)

Israel today, July 16, struck the General Staff of the Syrian army in Damascus. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } The Israeli defense army stated that it also...

Rawystye will get a job at the Kremlin churches in Zaporozhye – CNS

In the region of Zaporizhekhia, Russian invaders deploy a new phase of ideological expansion - the construction of temples under the control of the Russian Orthodox Church in the framework of the Berdsk Diocese. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22...

The Council voted for imposing an SBU account for 10 of these. man

Rada Verkhovna supported an increase in the number of SBU employees by 10 thousand people. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } 311 MPS voted for the corresponding bill...

People’s Deputies organized a fight in Supreme Rada (video)

The collision in the Verkhovna Session Hall of Rada occurred on Wednesday, July 16. .in_text_content_22 {width: 300px; Height: 600px; } @Media (min-width: 600px) {.in_text_content_22 {width: 580px; Height: 400px; }} .Adsbygoogle {Touch-Action: Manipulation; } Deputies of people Alexei Goncharenko and Danilo Getmanthev...