Malware

CRON#TRAP Campaign Attacking Windows Machine With Weaponized Linux VMs

Weaponized Linux virtual machines are used for offensive cybersecurity purposes like “penetration testing” or “exploiting vulnerabilities.” These setups often use the tools and frameworks that are designed for ethical hacking.

Securonix researchers recently detected CRON#TRAP campaign that has been attacking Windows machines with weaponized Linux virtual machines.

CRON#TRAP Campaign Attacking Windows Machine

CRON#TRAP is a sophisticated cyber attack campaign that begins with a “phishing email” containing a malicious shortcut (‘.lnk’) file disguised as “OneAmerica Survey.”

OneAmerica Survey.zip (Source – Securonix)

When executed, this file launches a “hidden 285MB package” that deploys a legitimate virtualization tool “QEMU” (Quick Emulator) which is renamed as “fontdiag.exe” to avoid detection. 

Build an in-house SOC or outsource SOC-as-a-Service -> Calculate Costs

The attack creates a hidden Linux environment running “Tiny Core Linux,” complete with a pre-configured backdoor that establishes a connection to a “C2” server automatically. 

This environment is dubbed “PivotBox” and contains custom commands like “get-host-shell” and “get-host-user” for host-system interaction by using “SSH keys” for persistent access. 

PivotBox (Source – Securonix)

The threat actors employed several tools, including vim, openssh, and 7zip, to manipulate the system while maintaining persistence via modified “boot local.sh” scripts and backed-up configurations via “file tool. sh. “

The primary targets of this campaign are “North America” and “Europe.”

This is concerning as it uses QEMU and operates within a hidden virtual environment, making it extremely difficult for traditional AV solutions to detect. 

While the sophisticated infrastructure of the malware contains:- 

  • Network testing capabilities.
  • Payload manipulation through a file called ‘crondx.’
  • Data exfiltration channels using free file-sharing services.

This highlights a well-planned multi-stage attack methodology that is designed for “long-term stealth” and “system compromise.”

The analysis of “crondx” (Chisel) reveals a sophisticated cyber attack component found within the “CRON#TRAP campaign,” where a pre-configured “64-bit ELF” executable serves as a critical backdoor mechanism.

crondx (Source – Securonix)

This ELF executable is located at “/home/tc/crondx” in a Linux “QEMU” instance.

While this Golang-compiled binary is mainly engineered to establish “covert communication channels” with a C2 server at IP address “18.208.230[.]174” by using “websocket protocols” for data transmission. 

The attack sequence initiates via a phishing email containing a malicious “ZIP” file with a “.lnk” shortcut that triggers a “PowerShell script” to launch an emulated Linux environment via ‘QEMU.’ 

This effectively helps to evade traditional Windows-based AV detection systems. The threat actors modified the open-source “Chisel tunneling” tool that is used for legitimate “TCP/UDP” tunneling over HTTP with SSH security. 

It’s done by hardcoding connection parameters directly into the binary instead of requiring command-line configurations which helps in enhancing its “stealth capabilities.” 

This customized implementation enables persistent remote access via “encrypted channels,” that allow threat actors to deploy additional payloads to execute commands and exfiltrate data while remaining undetected, reads Securonix report.

The system’s compromise is further supported via various persistence mechanisms like “modified startup scripts” and “SSH key implementations.” 

Here, custom command aliases like ‘get-host-shell’ and ‘get-host-user’ facilitate direct interaction with the host machine within the isolated QEMU environment. 

.ash_history file (Source – Securonix)

The “.ash_history” file documents the activities of the threat actor like “tool installation,” “system reconnaissance,” and “payload deployment.” 

It shows a modular approach to system infiltration that uses legitimate software tools (‘QEMU’ and ‘Chisel’) to maintain persistent access while evading security controls.

Recommendations

Here below we have mentioned all the recommendations:-

  • Avoid downloading unsolicited files or attachments.
  • Treat external download links as potential threats.
  • Monitor common malware staging directories, especially for scripts.
  • Watch for legitimate software running from unusual locations.
  • Enable robust endpoint logging for better detection.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago