Rewterz Threat Advisory – Multiple Apple macOS Vulnerabilities
July 26, 2023Rewterz Threat Alert – Banking Sector Targeted In Open-Source Software Supply Chain Attacks – Active IOCs
July 26, 2023Rewterz Threat Advisory – Multiple Apple macOS Vulnerabilities
July 26, 2023Rewterz Threat Alert – Banking Sector Targeted In Open-Source Software Supply Chain Attacks – Active IOCs
July 26, 2023Severity
High
Analysis Summary
GootLoader – a multi-staged JavaScript malware package, has been seen in the wild since late 2020. It initially gained popularity as a sophisticated multi-staged downloader of GootKit malware. This dropper’s payload delivery has progressed over time, and its payload capabilities have expanded beyond only distributing its namesake malware. Previously, this threat has delivered the information-stealing malware “GootKit,” from which it derives its name.
GootLoader leverage SEO poisoning tactics to prominently promote links to its malware in internet search results, drawing in as many unknowing victims as possible. The group was also seen utilizing overlays to show a fake forum page over blog articles with highly targeted material related to government, finances, legal, healthcare, and education.
Impact
- Information Theft
- Unauthorized Access
- SEO Poisoning
Indicators of Compromise
MD5
- bdbb48d423e2229e443db84cf2fa9d1e
- 377ac47cb17fdb3d824371c54dce9c0f
SHA-256
- 1010e2e196c40713218f2f71a0baf5a707f414bd7d838e64b2a32f26ad53bb35
- 1c12839fc73a316f88b2a2f65a5498d5f6f6039ac01e811c8b5e39ebc87c54f8
SHA-1
- 4c5d6d994708cbfc84cf9a5c36e5f156df3fe2cf
- 9f42b2c5d749083ae081ea8774c29c8bffa906c1
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Never trust or open ” links and attachments received from unknown sources/senders.
- Do not download document ?les attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.