Returning FIN8 Backdooring with New Sardonic Malware
A recent research whitepaper published by BitDefender's security researchers outlines the evolving capabilities of FIN8 and differences between multiple BADHATCH versions in response to detecting a new malware being dubbed Sardonic.
FIN8 has been active since the beginning of 2016 and is best known for attacking industries like retail, restaurant, hospitality, healthcare, and entertainment with the goal of harvesting payment card information from point-of-sale (POS) systems. Their arsenal includes tools like BADHATCH, PoSlurp, PowerSniff and multiple Windows zero-day exploits with tactics like spear-phishing. Over the years, FIN8 has orchestrated multiple large-scale campaigns that have impacting hundreds of companies.
The Sardonic malware is a new C++-based backdoor being developed and deployed by FIN8 on targets via spear-phishing and social engineering campaigns. Functionalities of the new malware include the following:
- system information harvesting
- command execution on compromised devices
- plugin system designed to load and execute further malware payloads delivered as DLLs
Comments
Post a Comment