New Ransomware Exploit Kit Blends with Credential Theft Ability

A new campaign has come to light that spreads the CryptoWall 4.0 (file-encrypting ransomware program) using Angler exploit kit by inserting malicious coding into hacked web pages.

This campaign was exposed by Denmark-based IT security firm Heimdal Security that involves installing various malware on the already compromised computer.

Initially the notorious data stealer Pony is installed, which captures all usable usernames and passwords present on the system and sends the information to the C&C servers controlled by the attackers.

This is done to exploit legitimate access credentials on CMS system and web servers. Afterward, malicious script is injected on those websites to achieve large-scale distribution target.

The next phase involves the unfolding of the drive-by campaign through moving the victim from authentic website to a series of dedicated infectious domains, which install the Angler Exploit Kit.

Once installed, the Angler Exploit Kit scans for vulnerabilities infamous third-party software in the vulnerable Microsoft Windows processes, in case the user hasn’t updated the system.

According to the blog post:

Some of the websites that deliver this kit include are available on the researchers’ website.

This extensive campaign starts from a bulletproof host located in Ukraine while around 100 web pages in Denmark have already been exploited and injected with malicious script. However, this campaign is no more restricted to Europe.

The researchers were successful in blocking more than 200 infected domains which were being used by attackers to spread CryptoWall4.0 in this campaign.

In September 2015, the same researchers discovered Dridex Banking Malware and a critical security flaw targeting 142 million websites with ransomware. 

