Cybercriminals Masquerade as Trusted Brands to Distribute DanaBot and StealC Malware

Cybersecurity experts have uncovered an advanced campaign of information theft that disguises itself as well-known brands to spread malware like DanaBot and StealC.

This operation, carried out by Russian-speaking cybercriminals and collectively referred to as “Tusk,” includes various sub-campaigns that exploit the credibility of popular platforms to lure users into downloading malware through fake websites and social media accounts.

Kaspersky researchers Elsayed Elrefaei and AbdulRhman Alfaifi revealed, “All the active sub-campaigns host the initial downloader on Dropbox.” This downloader is tasked with delivering additional malware to the victim’s device, primarily info-stealers like DanaBot and StealC, along with clippers.

Out of the 19 identified sub-campaigns, three are still active. The “Tusk” codename stems from the word “Mammoth,” which the threat actors used in log messages related to the initial downloader. In Russian e-crime circles, “Mammoth” is slang for victims.

These campaigns also stand out for using phishing techniques to trick victims into divulging personal and financial information, which is then sold on the dark web or used to gain unauthorized access to gaming accounts and cryptocurrency wallets.

The first of the three ongoing sub-campaigns, called TidyMe, mimics the peerme[.]io platform with a fake site hosted on tidyme[.]io (along with tidymeapp[.]io and tidyme[.]app), prompting users to download a malicious program for both Windows and macOS systems. The malicious executable is distributed via Dropbox.

The downloader, an Electron application, asks the victim to complete a CAPTCHA before displaying the main interface while secretly downloading and running two additional malicious files in the background.

The payloads in this campaign are Hijack Loader artifacts that eventually launch a version of the StealC malware, capable of collecting a broad range of information.

The second sub-campaign, RuneOnlineWorld (“runeonlineworld[.]io”), involves a fake website that imitates an MMO game called Rise Online World, distributing a similar downloader that facilitates the deployment of DanaBot and StealC on compromised devices.

This campaign also uses Hijack Loader to distribute a Go-based clipper malware designed to monitor clipboard content and replace copied wallet addresses with an attacker-controlled Bitcoin wallet to execute fraudulent transactions.

The final active campaign, Voico, impersonates an AI translator project called YOUS (yous[.]ai) using a fake site, voico[.]io, to spread an initial downloader. Once installed, it prompts the victim to complete a registration form, capturing their credentials, which are then logged on the console.

The final payloads in this campaign behave similarly to those in the second sub-campaign, with the only difference being that the StealC malware communicates with a different command-and-control (C2) server.

“The campaigns […] highlight the ongoing and evolving threat posed by cybercriminals who skillfully imitate legitimate projects to deceive victims,” the researchers noted. “Their use of social engineering tactics like phishing, combined with multi-stage malware delivery, demonstrates the advanced capabilities of these threat actors.”

“By exploiting the trust users have in reputable platforms, these attackers effectively deploy various malware to steal sensitive information, compromise systems, and ultimately achieve financial gain.”

More Articles & Posts