Hackers Take Advantage of Trending Software Queries to Distribute FakeBat Malware

Cybersecurity experts have detected a notable increase in malware infections originating from malvertising campaigns promoting a loader known as FakeBat.

According to a technical analysis by the Mandiant Managed Defense team, these attacks are highly opportunistic, focusing on individuals searching for widely-used business software. The malware in question uses a compromised MSIX installer to execute a PowerShell script that downloads a secondary payload.

FakeBat, also referred to as EugenLoader and PaykLoader, is associated with a threat group named Eugenfest. The Google-owned threat intelligence team identifies the malware under the codename NUMOZYLOD and attributes the Malware-as-a-Service (MaaS) operation to the group UNC4536.

The attack vectors for FakeBat involve drive-by download methods that redirect users looking for popular software to fraudulent sites mimicking legitimate ones, which then host malicious MSI installers. Notable malware families distributed through FakeBat include IcedID, RedLine Stealer, Lumma Stealer, SectopRAT (also known as ArechClient2), and Carbanak, which is tied to the FIN7 cybercriminal group.

UNC4536’s strategy relies on malvertising to spread trojanized MSIX installers disguised as well-known applications such as Brave, KeePass, Notion, Steam, and Zoom. These installers are hosted on imitation websites designed to look like genuine software distribution platforms, deceiving users into downloading them.

A distinctive feature of these attacks is the use of MSIX installers that employ a configuration called startScript to execute a script before running the main application.

Essentially, UNC4536 functions as a malware distributor, with FakeBat serving as a delivery mechanism for subsequent payloads intended for their partners, including FIN7.

“NUMOZYLOD collects various system details, such as operating system information, domain membership, and installed antivirus products,” Mandiant noted. “Certain variants also capture the host’s public IPv4 and IPv6 addresses, transmitting this data to its command-and-control servers, and establish persistence by creating a shortcut (.lnk) in the StartUp folder.”

This revelation follows Mandiant’s recent disclosure of another malware downloader, EMPTYSPACE (also known as BrokerLoader or Vetta Loader), which was used by the financially-driven threat group UNC4990 for data exfiltration and cryptojacking against Italian targets.

More Articles & Posts