Malware

Beware of New AliGater Attacking Outdated Windows Users

Malvertising (malicious advertising) refers to the practice of embedding harmful code within online advertisements, which can lead to malware infections on users’ devices. 

This technique often exploits legitimate advertising networks, making it difficult for both users and publishers to detect infected ads.

Recently, the Gen Digital researchers found that a malvertising campaign dubbed “AliGater,” has been actively chasing users of outdated windows in Europe.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

AliGater Attacking Outdated Windows Users

AliGater is a sophisticated malvertising platform that primarily targets the outdated Windows (7 SP1, 8.1) and Chrome versions, mostly in Europe. 

Windows version distribution (Source – Gen Digital)

The attack chain begins with malicious ads redirecting to aligate.homes, which fingerprints users via “User-Agent” strings. 

AliGater infection chain (Source – Gen Digital)

Here, the exploitable targets encounter a fake CAPTCHA loading “captcha.js” from a dynamic “*.shop” domain. 

Fake CAPTCHA (Source – Gen Digital)

This script analyzes the victim’s environment (architecture, platform, WebGL, Chrome version) and delivers tailored exploits for the V8 JavaScript engine (CVE-2023-2033) and Windows TrueType font parsing (CVE-2011-3402). 

The multi-stage payload utilizes the following things:-

  • WebAssembly
  • XOR encryption
  • Shellcode injection
  • Process hollowing
AliGater stages (Source – Gen Digital)

Besides this, it creates elevated processes masquerading as legitimate Windows executables (“dllhost.exe,” “SearchIndexer.exe,” “spoolsv.exe,” “svchost.exe,” “taskhost.exe”) to deploy the Lumma stealer

The attack employs syscall requests and targets specific user agents. The most frequently targeted user agent is “Mozilla/5.0 (Windows NT 10.0, Win64, x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36”, highlighting the specific versions vulnerable to this attack, Gen Digital said.

AliGater’s infrastructure uses rapidly changing subdomains (format: {random_chars}.{two_random_words}.shop) and IP addresses within consistent ASNs. 

Interestingly, AliGater shares several characteristics with the Magniber ransomware campaign, including targeting methodology, unusual syscall invocation techniques, and similar string encryption methods. 

This suggests a possible connection or shared codebase between the two threats, potentially indicating that Magniber’s authors are offering their infrastructure as a service.

While the final payload delivered via this elaborate chain has been identified as the Lumma stealer, the infrastructure could potentially be used to distribute other types of malware as well.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14-day free trial

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago