Malware

GHOSTENGINE Malware Exploits Vulnerable drivers To Terminate EDR Agents

Researchers discovered REF4578, an intrusion set that uses vulnerable drivers to disable established security solutions (EDRs) for crypto mining and deploys a malicious payload known as GHOSTENGINE.

GHOSTENGINE is in charge of locating and running the machine’s modules. To download files from a configured domain, it mostly uses HTTP, with a backup IP in case the domain is unavailable. It also uses FTP as a backup protocol that includes embedded credentials. 

This campaign required an unusual level of complexity to ensure the XMRIG miner would be installed and persistent.

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

REF4578 Execution Flow

Elastic Security Labs reports that the REF4578 intrusion started on May 6, 2024, with the execution of a PE file called Tiworker.exe that was posing as the genuine Windows TiWorker.exe file. 

The telemetry recorded the following alarms, which suggested that a known vulnerable driver had been used.

REF4578 Execution Flow

This file downloads and runs a PowerShell script that manages the intrusion’s whole execution flow when it is executed. 

According to analysis, this program executes a hardcoded PowerShell command line to obtain an obfuscated script called get.png. This script is then used to download more tools, modules, and configurations from the attacker C2.

The powershell script attempts to disable Windows Defender, enable remote services and clean the Windows event log channels. 

get.png disabling Windows Defender and enabling remote services

Next, to establish persistence, get.png creates the OneDriveCloudSync,DefaultBrowserUpdate, and OneDriveCloudBackup scheduled tasks as SYSTEM.

GHOSTENGINE installs a number of modules that can check for software updates, build with security tools, and construct a backdoor.

The main function of the smartscreen.exe module is to end any running EDR agent processes before downloading and setting up a cryptocurrency miner.

“The ultimate goal of the REF4578 intrusion set was to gain access to an environment and deploy a persistent Monero crypto miner, XMRig”, researchers said.

Recommendation

As a result, it is imperative that the following early acts be prevented and detected first:

  • Suspicious PowerShell execution
  • Execution from unusual directories
  • Elevating privileges to system integrity
  • Deploying vulnerable drivers and establishing associated kernel mode services.

ANYRUN malware sandbox’s 8th Birthday Special Offer: Grab 6 Months of Free Service

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago