Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Locked BEWARE: Doctor Web identifies pirated Windows builds with crypto stealer that penetrates EFI partition

Status
Not open for further replies.
https://news.drweb.com/show/?i=14712&lng=en
https://www.bleepingcomputer.com/news/security/pirated-windows-10-isos-install-clipper-malware-via-efi-partitions/
June 13, 2023

Doctor Web has discovered a malicious clipper program in a number of unofficial Windows 10 builds that cybercriminals have been distributing via a torrent tracker. Dubbed Trojan.Clipper.231, this trojan app substitutes crypto wallet addresses in the clipboard with addresses provided by attackers. As of this moment, malicious actors have managed to steal cryptocurrency in an amount equivalent to about $19,000 US.


At the end of May 2023, a customer contacted Doctor Web with their suspicion that their Windows 10 computer was infected. The analysis our specialists carried out confirmed the presence of trojan applications in the system. These were Trojan.Clipper.231 https://vms.drweb.com/search/?q=Trojan.Clipper.231&lng=en stealer malware as well as the Trojan.MulDrop22.7578 https://vms.drweb.com/search/?q=Trojan.MulDrop22.7578&lng=en dropper and Trojan.Inject4.57873 https://vms.drweb.com/search/?q=Trojan.Inject4.57873&lng=en injector, which were used to launch the clipper. Doctor Web’s virus laboratory successfully localized all these threats and neutralized them.

At the same time, it was discovered that the targeted operating system was an unofficial build and the malicious apps were built into it from the beginning. The following investigation revealed several such infected Windows builds:
  • Windows 10 Pro 22H2 19045.2728 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2913 + Office 2021 x64 by BoJlIIIebnik [RU, EN].iso
  • Windows 10 Pro 22H2 19045.2913 x64 by BoJlIIIebnik [RU, EN].iso
All of them were available for download on one of the torrent trackers, but it is possible that malicious actors are also using other sites to distribute infected system ISO images.

The malicious apps in these builds are located in the system directory:
  • \Windows\Installer\iscsicli.exe (Trojan.MulDrop22.7578)
  • \Windows\Installer\recovery.exe (Trojan.Inject4.57873)
  • \Windows\Installer\kd_08_5e78.dll (Trojan.Clipper.231)
Qq2RPJ.png


The clipper malware initialization occurs in several stages. In the first stage, the Trojan.MulDrop22.7578 malicious program is launched via the system Task Scheduler:

Code:
%SystemDrive%\Windows\Installer\iscsicli.exe

This dropper’s task is to mount an EFI system partition to the M:\ drive and copy two other malicious components onto it, after which it is to delete the original trojan files from the C:\ drive, launch Trojan.Inject4.57873, and then unmount the EFI partition.

In turn, Trojan.Inject4.57873 uses the Process Hollowing technique to inject Trojan.Clipper.231 into the %WINDIR%\\System32\\Lsaiso.exe system process. After that, the clipper operates in the context of this process.

Upon taking control, Trojan.Clipper.231 proceeds with monitoring the clipboard and substitutes the crypto wallet addresses copied into it with attacker-provided addresses. At the same time, the trojan has several limitations. First, the clipper begins substituting the addresses only if it detects the %WINDIR%\\INF\\scunown.inf system file. Second, the trojan verifies active processes. If it detects the processes of a number of apps that pose a threat to it, it will not substitute the crypto wallet addresses.

The infiltration of malware into the EFI partition of computers as an attack vector is still very rare. Therefore, the identified case is of a great interest for information security specialists.

Based on our specialists’ calculations, at the time of this news release, malicious actors have used Trojan.Clipper.231 to steal 0.73406362 BTC and 0.07964773 ETH, which is equivalent to the sum of $18,976.29 US.

Doctor Web recommends that users download only original ISO images of operating systems and only from trusted sources, such as manufacturers’ websites. The Dr.Web anti-virus successfully detects and neutralizes Trojan.Clipper.231 and the other malicious programs related to it, so they pose no threat to our users.
 

DGrigorescu

✅ Verified Member
Member
Downloaded
310.8 GB
Uploaded
1.9 TB
Ratio
6.27
Seedbonus
24,490
Upload Count
0 (0)
Member for 5 years
Thanks. It is a known fact that pirated software may contain viruses. That’s why exists TeamOS. But even with trusted sources like TeamOS it’s good to scan files and/or monitor your computer frequently.
 

mobi0001

The Power Is Yours!!!
Uploader
Power User
✅ Verified Member
Member
Downloaded
62.3 GB
Uploaded
11.3 TB
Ratio
186
Seedbonus
975
Upload Count
89 (104)
Member for 4 years
Thanks. It is a known fact that pirated software may contain viruses. That’s why exists TeamOS. But even with trusted sources like TeamOS it’s good to scan files and/or monitor your computer frequently.
Very true. I never use unknown or too shining ones, cause you never know. :)
 

bardia777

Member
Downloaded
4.8 GB
Uploaded
5.5 GB
Ratio
1.15
Seedbonus
1,454
Upload Count
0 (0)
Member for 4 years
Does the 'BoJlIIIebnik' or any another team like that exist in TeamOS?
 

mobi0001

The Power Is Yours!!!
Uploader
Power User
✅ Verified Member
Member
Downloaded
62.3 GB
Uploaded
11.3 TB
Ratio
186
Seedbonus
975
Upload Count
89 (104)
Member for 4 years
Does the 'BoJlIIIebnik' or any another team like that exist in TeamOS?
Not that I know of. Plus TOS kind of takes care of such bad stuff.
 

bardia777

Member
Downloaded
4.8 GB
Uploaded
5.5 GB
Ratio
1.15
Seedbonus
1,454
Upload Count
0 (0)
Member for 4 years
Not that I know of. Plus TOS kind of takes care of such bad stuff.
Let's say that x person uploaded a .iso file incl. virus and VirusTotal didn't even detect it.
How does TOS is going to prevent it?
 

bardia777

Member
Downloaded
4.8 GB
Uploaded
5.5 GB
Ratio
1.15
Seedbonus
1,454
Upload Count
0 (0)
Member for 4 years
Sorry for spamming, New to forum.
 

DGrigorescu

✅ Verified Member
Member
Downloaded
310.8 GB
Uploaded
1.9 TB
Ratio
6.27
Seedbonus
24,490
Upload Count
0 (0)
Member for 5 years
There is an extremely little chance to happen this. That’s why for your peace of mind it’s better to scan files yourself.
 

Cyler

🤴 Super Admin
⚡OS Master
Downloaded
510.5 GB
Uploaded
24.5 TB
Ratio
49.16
Seedbonus
27,587
Upload Count
1 (1)
Member for 6 years
Let's say that x person uploaded a .iso file incl. virus and VirusTotal didn't even detect it.
How does TOS is going to prevent it?
To make it simple, we dont allow just anyone to upload. Apart from the usual virus scan, a person to become an OS uploader must earn the trust of the community and that's no easy task, takes time and several people will double and triple check the uploads.
Other than that there is nothing much more we can do as a site and that's why we always say "Scan whatever you download".
 

YoungZeus

Geordie Boy
Power User
✅ Verified Member
Member
Downloaded
31.9 GB
Uploaded
11.6 TB
Ratio
373.81
Seedbonus
2,699
Upload Count
6 (6)
Member for 10 years
I think after Cylers posting there is nothing more to say in this thread, I will leave to read but locking it off to additional comments
 
Status
Not open for further replies.
Top