Categories: NewsSecurity

New Spam Campaign Distributes Locky Ransomware and Kovter Trojan Simultaneously

Criminals have taken a liking to the idea of combining multiple types of malware into one distribution campaign. Malware Protection Center researchers discovered a string of email messages using malicious attachments to spread both Locky ransomware and the Kovter Trojan. It is not the first time these two types of malware are distributed in the same campaign, as dual-pronged spam campaigns have become more common as of late.

Criminals Step Up Malware Distribution

It is rather disconcerting to learn opening a malicious email attachment can introduce two different types of malware at the same time. As if the Locky ransomware is not annoying to deal with on its own, computer users will also be affected by the Kovter Trojan. This latter piece of malware specialized in click fraud, generating a lot of illegal advertisement revenue for criminals.

Through a malicious email attachment, criminals execute a script that contains links to multiple domains where the malware types are downloaded from. By making the attachment a .Ink file, the recipient may click it and have the payload download executed in the background. PowerShell scripts have become a fan favorite among criminals targeting Windows users these days, that much is certain.

Researchers discovered a total of five hardcoded domains in the script from where the malware can be downloaded. Both the Locky ransomware and Kovter Trojan payloads are hosted on these platforms, and it is expected more of these domains will continue to pop up over time. Although law enforcement agencies can take down these domains rather easily, criminals will not hesitate to create additional hosting solutions over time.

Related Post

As one would expect from these spam email campaigns, the message in question is a fake receipt for a spoofed USPS delivery email. In the attached zip file, there is the malicious .Ink file , which initiates the PowerShell script once opened. One interesting aspect about this script is how it checks if the file is downloaded successfully and if is at least 10KB in size. Once that has been verified, it will stop the process automatically.

Microsoft researchers feel the use of multiple domain names to download the payload from is a powerful obfuscation technique. Blacklisting one specific URL is a lot easier than dealing with a handful of different domains. Moreover, this method seems to hint at how criminals can easily add more servers to download the malicious payloads from if they want to. A very troublesome development, to say the least.

Perhaps the most worrisome aspect of this new malware distribution campaign is how criminals continue to update the payloads themselves. Both Kovter and Locky receive regular updates, which means the development of ransomware and click-fraud Trojans is still going on behind the scenes. Moreover, it goes to show criminals will continue to rely on multi-pronged distribution campaigns for malware and ransomware moving forward.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Starknet Introduces STRK20 To Bring Built-In Privacy To ERC-20 Tokens

The team behind Starknet has introduced a new token standard aimed at solving one of…

3 days ago

Meta Acquires Moltbook, A Social Network Built For AI Agents To Interact And Coordinate

In a move that highlights the growing race to build infrastructure for autonomous artificial intelligence,…

3 days ago

Polymarket Partners With Palantir To Develop AI Platform For Sports Betting Integrity

Prediction market platform Polymarket has entered a new partnership with Palantir Technologies and artificial intelligence…

3 days ago

Ethereum Foundation Begins Staking Treasury ETH Using Bitwise Infrastructure

The Ethereum Foundation has begun staking part of its treasury, marking a significant step in…

4 days ago

Cyberconnect And SurfAI Founder Reportedly Under Investigation In China

Fresh reports circulating in the crypto space suggest that Wei Jiequan, better known as Wilson…

4 days ago

Virtuals And dAI Launch ERC-8183 To Enable Trustless Agentic Commerce On Ethereum

The infrastructure powering autonomous AI agents on Ethereum is slowly coming together. Payments, trust layers,…

4 days ago