Black screen instead of a movie. Hackers learned to hide Trojans inside the "bat" MP4

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
916
Deposit
0$
Video files are sometimes needed not for banal viewing, but for sly masking of content. Censys specialists have found a campaign in which structurally correct, but unsuitable for the reproduction of MP4 files deliver NetSupport Manager. The legal remote administration program after the hidden installation gives the attackers constant control over the computer.

Censys did not find the original bait, so the current assumption is the fake CAPTCHA. A possible ClickFix is pointed out by clearing the history of commands in the Windows “Execute” window after infection. With this technique, the site convinces the person to insert and run the copied command, after which PowerShell loads the first component of the chain.

The primary script checks the computer name for the signs of the analysis environment, hides the PowerShell window and creates a second script in the %TEMP% folder. It accesses the server with the Chrome browser ID and downloads the file of 6.5 MB. The request looks like a normal download of media content, which helps to hide the transfer of malicious content from surface checks.

There is almost no video inside the MP4. The closed uuid unit occupies 99.95% of the file and stores the XOR key along with the PowerShell compressed script, which after unpacking grows to almost 17 MB. The container successfully passes a simple file type check, but has zero resolution and is deprived of decoding parameters, so standard players cannot open it.

The final script places the NetSupport Manager client in a random subfolder C:/Users/Public, disables visible elements of the program, and prescribes an autorun under the name SecurityHealth, similar to the Windows Defender component. The client then communicates with the control gateway at port 443. Censys counted 18 builds on 40 active nodes in six networks and four countries.

Simply opening such an MP4 in the computer does not infect, since the chain needs a previously running command. For protection, you can not insert commands from sites in “Execute”, PowerShell or terminal. Censys protective systems advise to mark MP4, which are not decoded or almost entirely composed of uuid blocks, and administrators should check the published indicators of compromise.
 
Top Bottom