{"id":57,"date":"2019-09-25T09:35:29","date_gmt":"2019-09-25T09:35:29","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=57"},"modified":"2021-05-01T16:34:38","modified_gmt":"2021-05-01T16:34:38","slug":"us-military-veterans","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/us-military-veterans\/","title":{"rendered":"Hackers Hosting Fake Military Veterans Website to Drop Malware"},"content":{"rendered":"\n<p>Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware&nbsp;by prompted users to download an app that turned out to be malware downloader.<\/p>\n\n\n\n<p>The app is also capable of deploying the other malware and dangerous spying tool to compromise the victims and steal the data from their system.<\/p>\n\n\n\n<p>The URL( <em>hxxp:\/\/hiremilitaryheroes[.]com<\/em>) that hosting to drop the malware looks very similar to the U.S. Chamber of Commerce,&nbsp;https:\/\/www.hiringourheroes.org. <\/p>\n\n\n\n<p>Researchers believe that the Tortoiseshell&nbsp;group was behind an attacker on an<a href=\"https:\/\/www.symantec.com\/blogs\/threat-intelligence\/tortoiseshell-apt-supply-chain\"> IT provider in Saudi Arabia<\/a> and also the malware using backdoor that is same as their use for the previous campaign.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>  U.S. Military Veterans Hiring Service  <\/strong><\/h2>\n\n\n\n<p>The fake website names as &#8220;Hire Military Heroes&#8221; which includes the images of a movie &#8220;Flags of our Fathers.&#8221; and quoted as &#8220;we make America safer&#8221;<\/p>\n\n\n\n<p>Also, the website claims that the desktop app is completely free by directing to users via three links but the app is totally fake and it acts as an installer.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/1.bp.blogspot.com\/-uy7Bdz4sIgo\/XYsEsrhU_HI\/AAAAAAAAERM\/MI269-6xbhc0hyDStEDGqihjbV7WyQzjQCLcBGAsYHQ\/s1600\/military%2B%25281%2529%2B%25281%2529.jpg\" alt=\"\" width=\"469\" height=\"293\"\/><\/figure><\/div>\n\n\n\n<p>The fake installer called the original malware installer to execute into the system and it starts showing the error message and claims that the security solution terminating the connection to the server.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/1.bp.blogspot.com\/-C_VfJHcbluY\/XYsF3zQ09sI\/AAAAAAAAERU\/MLgLFZftQ-Ehv-UqQh1X2PcPl9EjRstyQCLcBGAsYHQ\/s1600\/error%2B%25281%2529.jpg\" alt=\"\" width=\"505\" height=\"265\"\/><\/figure><\/div>\n\n\n\n<p>During the process of infection, the installer checks whether it can able to reach Google if no then the process will be terminated. if yes then it  downloads two binaries which are stored in base64 from <em>hxxp:\/\/199[.]187[.]208[.]75\/MyWS.asmx\/GetUpdate?val=UID<\/em>: <\/p>\n\n\n\n<p>Researchers observed that one of the binaries act as a tool to perform the reconnaissance stage&nbsp;and another binary is a remote admin tool, an executed as a service.<\/p>\n\n\n\n<p class=\"has-very-light-gray-background-color has-background\">According to Talos <a href=\"https:\/\/blog.talosintelligence.com\/2019\/09\/tortoiseshell-fake-veterans.html\">researchers <\/a>&#8221; If something fails during the installation, an email is sent to the attacker. The credentials are hardcoded in the installer. The email account is ericaclayton2020@gmail[.]com and the error email is sent to marinaparks108@gmail[.]com. &#8220;<\/p>\n\n\n\n<p>The malware has some of the interesting features which including the following<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>kill_me<\/strong>: It stops the service and removes the malware<\/li><li><strong>Upload<\/strong>: It downloads a file on the internet<\/li><li><strong>Unzip<\/strong>: It uses PowerShell to unzip and execute code on the system<\/li><li>And finally, the malware can execute a command<\/li><\/ul>\n\n\n\n<p> This new campaign utilizing the malicious hiring website represents a massive shift for Tortoiseshell.<\/p>\n\n\n\n<p>Based on the attack scenario, there are high chances to fall a large people become the victims and also the website looks easily attract to the social media.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h.rndzlw9ljinh\"><strong>IOC&#8217;s<\/strong><\/h2>\n\n\n\n<p class=\"has-very-light-gray-background-color has-background\"><strong>Installers:<\/strong><br><br>c121f97a43f4613d0a29f31ef2e307337fa0f6d4f4eee651ee4f41a3df24b6b5<br>2a9589538c563c006eaf4f9217a192e8a34a1b371a31c61330ce2b396b67fd10<br>55b0708fed0684ce8fd038d4701cc321fe7b81def7f1b523acc46b6f9774cb7b<br><br><strong>Reconnaissance PE:<br><\/strong><br>ec71068481c29571122b2f6db1f8dc3b08d919a7f710f4829a07fb4195b52fac<br><br><strong>RAT:<\/strong><br><br>51d186c16cc609ddb67bd4f3ecd09ef3566cb04894f0496f7b01f356ae260424<br><br><strong>Additional IOCs related to this actor<br><\/strong><br>41db45b0c51b98713bc526452eef26074d034b2c9ec159b44528ad4735d14f4a<br>78e1f53730ae265a7eb00b65fbb1304bbe4328ee5b7f7ac51799f19584b8b9d4<br>46873290f58c25845b21ce7e560eae1b1d89000e887c2ff2976d931672390dd8<br>f31b5e14314388903a32eaa68357b8a5d07cbe6731b0bd97d2ee33ac67ea8817<br>f1c05ff306e941322a38fffb21dfdb5f81c42a00a118217b9d4e9807743d7275<br>1848f51d946fa8b348db8ef945a1ebff33ff76803ad26dfd175d9ea2aa56c7d0<br>ed150d9f6e12b6d669bcede3b7dc2026b7161f875edf26c93296e8c6e99152d5<br>2682328bde4c91637e88201eda5f5c400a3b3c0bdb87438d35660494feff55cf<br>e82a08f1514ccf38b3ae6b79e67d7605cb20b8377206fbdc44ddadfb06ae4d0d <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The website claims that the desktop app is completely free by directing to users via three links but the app is totally fake and it acts as an installer.<\/p>\n","protected":false},"author":3,"featured_media":4904,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"http:\/\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png","fifu_image_alt":"Military Veterans","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[268,274,275],"class_list":{"0":"post-57","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-malware-attack","10":"tag-military-veterans","11":"tag-military-veterans-website"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hackers Hosting Fake Military Veterans Website to Drop Malware<\/title>\n<meta name=\"description\" content=\"Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware by prompted users to download an app that turned out to be malware downloader.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/us-military-veterans\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Hosting Fake Military Veterans Website to Drop Malware\" \/>\n<meta property=\"og:description\" content=\"Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware by prompted users to download an app that turned out to be malware downloader.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/us-military-veterans\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2019-09-25T09:35:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-01T16:34:38+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png\" \/>\n<meta name=\"author\" content=\"Balaji N\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"http:\/\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/balaji_gbh\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Balaji N\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hackers Hosting Fake Military Veterans Website to Drop Malware","description":"Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware by prompted users to download an app that turned out to be malware downloader.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/us-military-veterans\/","og_locale":"en_US","og_type":"article","og_title":"Hackers Hosting Fake Military Veterans Website to Drop Malware","og_description":"Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware by prompted users to download an app that turned out to be malware downloader.","og_url":"https:\/\/cybersecuritynews.com\/us-military-veterans\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2019-09-25T09:35:29+00:00","article_modified_time":"2021-05-01T16:34:38+00:00","og_image":[{"url":"http:\/\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png","type":"","width":"","height":""}],"author":"Balaji N","twitter_card":"summary_large_image","twitter_image":"http:\/\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png","twitter_creator":"@https:\/\/twitter.com\/balaji_gbh","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Balaji N","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/"},"author":{"name":"Balaji N","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/0ad7770df28fe608567609e4ba1c4da2"},"headline":"Hackers Hosting Fake Military Veterans Website to Drop Malware","datePublished":"2019-09-25T09:35:29+00:00","dateModified":"2021-05-01T16:34:38+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/"},"wordCount":657,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png?w=728&resize=728,380&ssl=1","keywords":["malware attack","Military Veterans","Military Veterans website"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2019","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/","url":"https:\/\/cybersecuritynews.com\/us-military-veterans\/","name":"Hackers Hosting Fake Military Veterans Website to Drop Malware","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png?w=728&resize=728,380&ssl=1","datePublished":"2019-09-25T09:35:29+00:00","dateModified":"2021-05-01T16:34:38+00:00","description":"Researchers discovered a fake website that posed as U.S. Military Veterans hiring service provider and drops the powerful malware by prompted users to download an app that turned out to be malware downloader.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/us-military-veterans\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#primaryimage","url":"https:\/\/i2.wp.com\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png?w=728&resize=728,380&ssl=1","contentUrl":"https:\/\/i2.wp.com\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png?w=728&resize=728,380&ssl=1","width":"728","height":"380","caption":"Military Veterans"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/us-military-veterans\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Hackers Hosting Fake Military Veterans Website to Drop Malware"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/0ad7770df28fe608567609e4ba1c4da2","name":"Balaji N","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031?s=96&d=mm&r=g","caption":"Balaji N"},"description":"BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief &amp; Co-Founder - Cyber Security News &amp; GBHackers On Security.","sameAs":["https:\/\/www.linkedin.com\/company\/cybersecurity-news\/","https:\/\/x.com\/https:\/\/twitter.com\/balaji_gbh"],"url":"https:\/\/cybersecuritynews.com\/author\/balaji\/"}]}},"jetpack_featured_media_url":"https:\/\/i2.wp.com\/2.bp.blogspot.com\/-AUlak6IjEcc\/XYswY9a5xPI\/AAAAAAAAERw\/sy62A2JDt1crX2Q_UwJKI8pxtqes6PtxACK4BGAYYCw\/s1600\/Military%2BVeterans.png?w=728&resize=728,380&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/57","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=57"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/57\/revisions"}],"predecessor-version":[{"id":5856,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/57\/revisions\/5856"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/4904"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=57"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=57"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=57"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}