This new threat infects devices with a dozen malware at once

this new threat infects devices with a dozen malware at once

This new threat infects devices with a dozen malware at once

Cybersecurity researchers from Outpost24’s KrakenLabs observed a new and quite unique malware campaign that seems to values quantity over quality.

Usually, when hackers compromise a device, they deploy a single piece of malware and try their best to remain unseen and persistent, as they use the computer for whatever end goal they have.

But this new campaign, dubbed Unfurling Hemlock, does the exact opposite, making it stand out in the world of cybercrime. The researchers are saying that once the victim triggers the malware executable - in this case called ‘EXTRACT.EXE’ - they receive a handful of different malware, infostealers, and botnet executables.

Malware cluster bomb

The chances of the malware being picked up by cybersecurity solutions is high, but the researchers believe the attackers are hoping at least some of the payloads will survive the purge. Among the things dropped on the devices are Redline (popular infostealer), RisePro (an upcoming infostealer), Mystic Stealer (infostealing malware-as-a-service), Amadey (loader), SmokeLoader (another loader), Protection Disabler (a utility that disables Windows Defender and other security features), Enigma Packer (obfuscation tool), Healer (anti-security solution), and Performance Checker (a utility that checks and logs the performance of malware execution).

This “malware cluster bomb” was first spotted in February 2024, the researchers said, claiming to have seen more than 50,000 cluster bomb files, all with unique characteristics that link them back to Unfurling Hemlock.

KrakenLabs could not say with absolute certainty who the threat actors behind Unfurling Hemlock are, but they are fairly confident they are of Eastern European origin. Some of the evidence pointing in that direction is the use of Russian language in some of the samples, and the use of the Autonomous System 203727, related to a hosting service cybercrime groups in the region usually use.

Luckily enough, the malware being pushed through this campaign is well-known and most reputable antivirus programs will flag it.

Via BleepingComputer

More from TechRadar Pro

    OTHER NEWS

    12 minutes ago

    Redbox owner Chicken Soup for the Soul files for bankruptcy

    12 minutes ago

    There is no end in sight for China’s uneven economic recovery

    12 minutes ago

    Arby’s Is Bringing Back a Fan-Favorite Menu Item for the First Time in 3 Years

    12 minutes ago

    McDonald's in major menu shakeup with 3 new items and some returning favourites

    12 minutes ago

    This is a 40mph scale replica of Nigel Mansell’s Williams FW14B

    13 minutes ago

    New Zealand rugby chief says the sport needs to bring in 20-minute red cards

    13 minutes ago

    “Straight Outta Compton ”Producer Will Packer to Publish New Book: ‘My Most Personal Project to Date’ (Exclusive)

    13 minutes ago

    UAE timings: all the fixtures for the knock out stages of the Euros

    13 minutes ago

    'Inside Out 2' crosses billion-dollar box office mark

    13 minutes ago

    The best sleeping bags for camping, festivals and hiking, tried and tested

    13 minutes ago

    Nationals call up top prospect James Wood, to debut vs. Mets

    13 minutes ago

    Kids spend a lot of time outside in the summer. Here's how to deal with their common injuries

    13 minutes ago

    The Supreme Court rules for a North Dakota truck stop in a new blow to federal regulations

    14 minutes ago

    Dutch Olympic organizers stand by qualification of athlete convicted of rape

    15 minutes ago

    Hamilton Ticats remain winless after dropping heartbreaker in Ottawa

    15 minutes ago

    Mark Cuban is offloading a portion of his NFTs—one already sold for over $30,000

    17 minutes ago

    Wimbledon favourite 'heartbroken' after difficult call

    17 minutes ago

    Tyla makes history with New African Music Performance win

    17 minutes ago

    Bando Stone & The New World official trailer

    17 minutes ago

    Steve Bannon gets what Ghislaine wanted: Look at the 'Orange is the New Black' prison ex-Trump adviser will spend his summer locked away in

    17 minutes ago

    Controversial TV presenter drops vile gay slurs on podcast - and you won't believe his defence: 'I don't care if you cancel me'

    18 minutes ago

    'The best lip gloss balm I've ever tried!' Shoppers are obsessed with this hydrating and tinted bareMinerals balm - and you can get THREE for just $49 (down from $75!)

    18 minutes ago

    Bobby Bonilla day: Fans go wild as ex-MLB star, 61, gets another $1.19m payout from New York Mets - and he'll keep getting paid until 2035!

    18 minutes ago

    Tesco shoppers slam 'bleak' sign of the times as olive oil becomes latest kitchen staple to be security tagged after price of 'liquid gold' soars to up to £18 per bottle

    18 minutes ago

    The early Amazon Prime Day sale sees DEEP discounts on home essentials: Shop 24 big bargains from Shark, Dyson, Ninja, KitchenAid, and so much more - prices start at $15!

    18 minutes ago

    'Best natural deodorant on the market!': Say goodbye to your BO with this full-body deodorant that wowed Shark Tank investors

    18 minutes ago

    Jude Bellingham UNDER INVESTIGATION - and could face a ban - for his x-rated gesture in England's win over Slovakia, UEFA confirm, over 'violation of decent conduct' rules

    18 minutes ago

    Enjoy a glass of wine? Thank the asteroid that killed the dinosaurs! Scientists say the extinction of the ancient reptiles paved the way for grapes to spread

    18 minutes ago

    Taliban to press international community on Afghanistan economic sanctions

    18 minutes ago

    Trump Awaits Immunity Ruling, and the French Far Right Wins Big

    18 minutes ago

    The 'oldest Taylor Swift fan', 90, jets across the Atlantic to see her favourite singer in London and Paris

    18 minutes ago

    Kevin Dillon's Tesla abruptly stops 'mid-carwash' resulting in a fender bender with three cars behind him

    18 minutes ago

    Plans for new train services between London and Manchester

    18 minutes ago

    'She apologised': AFL admit huge umpiring blunder

    19 minutes ago

    Car sales plummet as electric vehicles see dramatic drop

    19 minutes ago

    As Wimbledon begins – how to perfect your tennis technique this summer

    19 minutes ago

    2024 US Olympic track trials: What you need to know about Team USA roster

    19 minutes ago

    NHL free agency live updates: Who has signed deals on first day?

    19 minutes ago

    Rainy mornings, afternoons and some warm nights in Singapore in first half of July: Weatherman

    19 minutes ago

    Gen Zers are so disillusioned with the economy that they think it’s OK to commit fraud