Malvirt

Malware Profile Updated 3 months ago
Download STIX
Preview STIX
MalVirt is a malicious software (malware) that has been observed to be distributed through malvertising attacks, using virtualized .NET malware loaders. The malware infects systems via suspicious downloads, emails, or websites, and once inside, it can disrupt operations, steal personal information, or even hold data hostage for ransom. SentinelOne's senior threat researcher Aleksandar Milenkoski discovered that the MalVirt loaders are distributing malware from the Formbook family, an infostealer malware. This discovery was part of an ongoing campaign at the time of writing, according to a SentinelOne advisory. In the past, Formbook and XLoader malware have typically been distributed via phishing emails and "malspam" via Macro-enabled Office documents. However, the new MalVirt campaign suggests a shift towards these types of malware being distributed through malvertising. The distribution of this malware through the MalVirt loaders is characterized by an unusual amount of applied anti-analysis and anti-detection techniques. Some MalVirt samples also determine whether they are executing in a virtual machine or sandbox environment, often querying registry keys to detect the VirtualBox or VMware environments. The individuals behind the Formbook and XLoader malware are demonstrating their ability to expand beyond phishing and adopt the growing trend of malvertising through the distribution of MalVirt. This includes the use of signatures and countersignatures from companies like Microsoft, Acer, DigiCert, Sectigo, but with invalid certificates or untrusted systems. SentinelOne first encountered a MalVirt sample during a routine Google search for "Blender 3D." The researchers were subsequently struck by the lengths the miscreants went to evade detection and analysis of the loaders and info-stealing malware.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Formbook
2
Formbook is a type of malware known for its ability to steal personal information, disrupt operations, and potentially hold data for ransom. The malware is commonly spread through suspicious downloads, emails, or websites, often without the user's knowledge. In June 2023, Formbook was observed being
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malvertising
Malware
Phishing
Decoy
Sandbox
Microsoft
Azure
Net
Exploit
Infostealer ...
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
BlenderUnspecified
1
Blender, a renowned threat actor known for its involvement in the cybersecurity landscape, has recently been under scrutiny due to its alleged role in facilitating illegal transactions. Last year, the US imposed sanctions on crypto mixers Tornado Cash and Blender, targeting them as part of a broader
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Malvirt Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
InfoSecurity-magazine
a year ago
XLoader MacOS Malware Variant Returns With OfficeNote Facade
CERT-EU
4 months ago
12 Months of Fighting Cybercrime & Defending Enterprises | #cybercrime | #infosec | National Cyber Security Consulting
InfoSecurity-magazine
7 months ago
New Research: Tackling .NET Malware With Harmony Library
CERT-EU
a year ago
Malvertising attacks are distributing .NET malware loaders
InfoSecurity-magazine
a year ago
MalVirt Loaders Exploit .NET Virtualization to Deliver Malvertising Attacks