By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    Malware Reigned Supreme In 2012
    12 months ago
    BEWARE THE THINGBOT!
    12 months ago
    Is your PC a part of botnet? Check it!
    12 months ago
    Latest News
    Beware of scammers! Dangerous apps in the App Store
    8 hours ago
    How To Limit Login Attempts on WordPress (+ Should You?)
    1 day ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (September 18, 2023 to September 24, 2023)
    1 day ago
    Two privilege escalation vulnerability in Simple Membership Plugin
    2 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    The creator of malware has infected her own computer
    12 months ago
    Windows 11 build 25163 out with new Taskbar Overflow feature
    12 months ago
    How to fix Microsoft Store not working on Windows 11
    12 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    8 months ago
    Now you can speed up any video in your browser
    8 months ago
    How to restore access to a file after EFS or view it on another computer?
    8 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    9 months ago
  • How To
    How ToShow More
    Cloudflare now uses post-quantum cryptography to talk to your origin server
    Cloudflare now uses post-quantum cryptography to talk to your origin server
    11 hours ago
    Privacy-preserving measurement and machine learning
    Privacy-preserving measurement and machine learning
    11 hours ago
    Encrypted Client Hello – the last puzzle piece to privacy
    Encrypted Client Hello – the last puzzle piece to privacy
    11 hours ago
    Reminder: Enable two-factor authentication wherever you have it. This business
    14 hours ago
    ​​Know exactly when your data is transferred to GoogleIn a world where our data is permanent
    14 hours ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to hide a file or folder on an Android device?
    12 months ago
    Image instead of Ethereum cryptocurrency
    12 months ago
    How to install Split APKs?
    12 months ago
    Latest News
    How to enable extensions for Google Bard AI
    9 hours ago
    Window 11 Copilot: 10 Best tips and tricks
    16 hours ago
    How to create AI images with Cocreator on Paint for Windows 11
    2 days ago
    How to install September 2023 update with 23H2 features for Windows 11
    3 days ago
  • Glossary
  • My Bookmarks
Reading: Adwind malware-as-a-service infecting hundreds of thousands devices
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
ThreatsWordpress Threats

Adwind malware-as-a-service infecting hundreds of thousands devices

Vitus White
Last updated: 19 October
Vitus White 4 years ago
Share
7 Min Read

At the Security Analyst Summit 2016 our Global Research and Analysis Team (GReAT) has published extensive research on the Adwind Remote Access Tool (RAT). This malicious tool is also known as AlienSpy, Frutas, Unrecom, Sockrat, JSocket and jRat. It has been developed for several years and distributed through a single malware-as-a-service platform, which means that anyone can pay small dollars (from $25 to $300) for the service and use the malicious tool to their advantage.

Adwind malware-as-a-service hits more than 400,000 users globally

Our GReAT researchers discovered this malware platform during the attempted targeted attack against a bank in Singapore. The malware came in form of a malicious Java-file attached to a spear-phishing email, which was received by a targeted employee at the bank. Basically, it was a typical example of how this malware can be distributed.

Several features of this malware piqued the attention of the researchers. First of all, it was able to run on multiple platforms: aside from Windows it could infect Linux, OS X and Android operating systems. Though Java is not a common platform for malware at all, it is still considered the second biggest security vulnerability that requires constant patching, while the first is definitely Adobe’s Flash plugin. Moreover, Java applications by design are capable of running on any operational system. This makes Java very convenient surrounding for those who want to develop multi-platform malware. This is basically why Oracle is really putting a lot of effort into improving Java’s security.

Oracle to Kill Java Browser Plugin: https://t.co/aF0qj9WWWV via @threatpost #RIPJAVA pic.twitter.com/5kbts0mNcD

— Kaspersky Lab (@kaspersky) January 28, 2016

The second thing that stood out of the malware discovery was that it was not picked up by any anti-virus program.

Thirdly, it was very capable: the list of its functions included the ability to collect keystrokes; steal cached passwords, VPN certificates and cryptocurrencies wallets’ keys; take screenshots; record video, photos and sound from computer’s microphone and webcam; collect user and system information; manage SMS in case of Android OS, and so on. As you see, the only thing that limited criminals was their skills and imagination.

Shortlist of JSocket features. Only *short* list #TheSAS2016 pic.twitter.com/9SYObtskbZ

— Eugene Kaspersky (@e_kaspersky) February 8, 2016

All in all, it’s a very mighty multi-platform spying tool. After investigation of the malware’s activity our researchers came to the conclusion that the very story of Adwind malicious toolkit is far more thrilling than it might seem at the beginning.

It turned out, that this malware is being developed for several years, with first samples dating back to 2012. At different periods of time it had different names: its creators branded it as Frutas in 2012, as Adwind in 2013, as Unrecom and AlienSpy in 2014 and as JSocket in 2015.

AlienSpy RAT Resurfaces as JSocket via @threatpost https://t.co/5ZWmhpGiKm pic.twitter.com/koTpglGJjP

— Kaspersky Lab (@kaspersky) August 24, 2015

GReAT experts believe that there is only one hardworking individual behind the Adwind platform, who has been developing and supporting new features and modules for at least the last four years. Despite all the fuss about Java security, the platform was not created to make cybercriminal’s life easier, and the author of the Adwind malware had to come up with a number of workarounds to make the whole scheme work. Of course, this person might also pass some tasks to the shoulders of outsourcers, but all the efforts seem to be covered by a good revenue: as far as we calculated, the whole service might bring $200,000 per year. Still you should take into account that the latest version of the portal was started only in summer 2015 so the criminal might still be waiting for the money.

Adwind malware-as-a-service hits more than 400,000 users globally

In the beginning the platform had only a Spanish interface, but later it got an English interface. With that update Adwind became recognized globally by cybercriminals of all stripes, including scammers performing advanced frauds, unfair business competitors, cyber-mercenaries who are hired to spy on people and organizations. It can also be used by anyone who wants to spy on people that they know.

The geography of victims also changed during these years. In 2013 Arabic and Spanish-speaking countries were under fire. The next year criminals aimed at Turkey and India, followed by UAE, the US and Vietnam. In 2015 Russia was at the top, with UAE, Turkey, USA and Germany next to it. It is understandable, as now Adwind is sold to different cyberciminals who live around the world.

Adwind malware-as-a-service hits more than 400,000 users globally

As far as we know, there were more than 443 thousand victims during these four years. It’s also noteworthy that we observed a large spike of infections in the end of 2015. Since August 2015 to January 2016 more than 68,0000 users encountered Adwind RAT malware samples. Moreover, in August 2015 this malware popped up in a cyber espionage story. It turned out, that one of Adwind solutions named AlienSpy had been used to spy on an Argentinian prosecutor, who was found dead in his apartment under mysterious circumstances, in January 2015.

.@vkamluk + @codelancer describing #Adwind, a cross-platform RAT found in some banks in Singapore. #TheSAS2016 pic.twitter.com/cu5myoF0kR

— Securelist (@Securelist) February 8, 2016

Criminals who bought and used Adwind kit targeted private individuals and small and medium businesses from a number of industries, including: manufacturing, finance, engineering, design, retail, government, shipping, telecom and a lot of others.

That’s why we can’t but encourage enterprises to review the purpose of using Java platform and disable it for all unauthorized sources.


Source: kaspersky.com

Translate this article

TAGGED: Linux, Malware, Phishing, PoC, Security, Targeted Attack, Threats, Windows, Windows 11
Vitus White October 19, 2022 September 30, 2019
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Cloudflare now uses post-quantum cryptography to talk to your origin server
Cloudflare now uses post-quantum cryptography to talk to your origin server
Apps 11 hours ago
Privacy-preserving measurement and machine learning
Privacy-preserving measurement and machine learning
Apps 11 hours ago
Encrypted Client Hello – the last puzzle piece to privacy
Encrypted Client Hello – the last puzzle piece to privacy
Apps 11 hours ago
Beware of scammers! Dangerous apps in the App Store
Threats 11 hours ago
How to enable extensions for Google Bard AI
News 12 hours ago

You Might Also Like

Cloudflare now uses post-quantum cryptography to talk to your origin server
Apps

Cloudflare now uses post-quantum cryptography to talk to your origin server

11 hours ago
Privacy-preserving measurement and machine learning
Apps

Privacy-preserving measurement and machine learning

11 hours ago
Encrypted Client Hello – the last puzzle piece to privacy
Apps

Encrypted Client Hello – the last puzzle piece to privacy

11 hours ago
Threats

Beware of scammers! Dangerous apps in the App Store

11 hours ago
Show More

Related stories

How to upgrade to Windows 11 23H2 with Installation Assistant
How to install September 2023 update with 23H2 features for Windows 11
Critical Vulnerability in Forminator Plugin
How to get the latest Windows 11 innovations
How to blur image background in Photos for Windows 11
How to download official Windows 11 23H2 ISO file
Previous Next

10 New Stories

Reminder: Enable two-factor authentication wherever you have it. This business
​​Know exactly when your data is transferred to GoogleIn a world where our data is permanent
​​Fake correspondence with the iPhone interfaceIn a world where digital communication is
​​Let's find out who is watching your Instagram stories from a fake Have you ever wondered
Window 11 Copilot: 10 Best tips and tricks
How To Limit Login Attempts on WordPress (+ Should You?)
Previous Next
Hot News
Cloudflare now uses post-quantum cryptography to talk to your origin server
Privacy-preserving measurement and machine learning
Encrypted Client Hello – the last puzzle piece to privacy
Beware of scammers! Dangerous apps in the App Store
How to enable extensions for Google Bard AI
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?