Researchers have discovered a search engine optimization poisoning campaign intended to lure users into installing malware on their computers. The campaign works by leveraging various SEO techniques, such as cramming tons of keywords into the source code of various malicious webpages, in order to raise those webpages near the top of the search results for various productivity applications that are free to download.
This campaign has two different infection chains. The first infection chain targets users looking for software bundles. A user who searches for something like “free software development tools installation” may see a compromised website among the search results on the first page and visit that site. If the user downloads and runs the software installer on the compromised site, it will install legitimate software, but bundled with that software is BATLOADER malware.
Once after the installation process, a multi-stage infection chain begins, where each stage involves downloading and executing an additional malicious payload. One of these payloads contains malicious VBScript embedded inside a legitimate internal component of Windows, AppResolver.dll. Despite the malicious VBScript, the DLL sample’s code signature remains valid, which is an issue that Microsoft attempted to address with a patch for CVE-2020-1599.
The second attack chain targets users looking for specific software, rather than software bundles. When a user searches for “free TeamViewer install, users are directed to the malicious website will find a message board with a download link for what appears to be legitimate software, but is really the ATERA Agent Installer Package. ATERA is legitimate Remote Monitoring and Management software, but the threat actors in this case use it to run pre-configured scripts, perform malicious tasks, install persistent malware, and finally uninstall itself, once its work is done.
Some of the attack chain activity overlaps with techniques used in CONTI ransomware operations. The threat group behind this SEO poisoning campaign may be replicating CONTI techniques, by drawing on training documents, playbooks, and tools that were leaked by a disgruntled CONTI affiliate in August 2021.
Indicators of Compromise