Lunar Spider Infected Windows Machine in Single Click and Harvested Login Credentials
A cybercriminal group identified as Lunar Spider successfully compromised a Windows system through a single malicious click, enabling them to harvest credentials and maintain access for nearly two months.
A cybercriminal group identified as Lunar Spider successfully compromised a Windows system through a single malicious click, enabling them to harvest credentials and maintain access for nearly two months.
The intrusion began in May 2024, illustrating how initial access can escalate to full domain compromise. The attack started when a user executed a heavily obfuscated JavaScript file disguised as a tax form, named "FormW-9Ver-i4053b043910-86g91352u7972-6495q3.js".
This file was reported by security researchers and associated with the Lunar Spider group. It contained minimal executable code dispersed among filler content to evade detection systems.
The JavaScript payload triggered the download of an MSI package from a remote server, deploying a Brute Ratel DLL file using the Windows utility rundll32.
This approach allowed the threat actors to inject Latrodectus malware into the explorer.exe process while establishing command and control communications with multiple CloudFlare proxied domains.
Within the first hour, the Latrodectus payload retrieved a specialized stealer module to harvest credentials from compromised systems.
The malware targeted 29 Chromium-based browsers, including Google Chrome, Microsoft Edge, Yandex Browser, Vivaldi, and others. Firefox was targeted through profile enumeration aiming at cookies.sqlite database files.
The intrusion began in May 2024, illustrating how initial access can escalate to full domain compromise.
The credential harvesting extended to email configurations from Microsoft Outlook (versions 11.0-17.0) by querying Windows registry keys. The stealer extracted server configurations, including SMTP, POP3, IMAP, and NNTP server addresses, port numbers, usernames, and encrypted passwords, granting attackers comprehensive access to the victim's communication infrastructure.
On day three, the attackers discovered an unattend.xml Windows Answer file containing plaintext domain administrator credentials from an automated deployment process.
On day four, a binary named lsassa.exe was deployed and executed via BackConnect on the compromised host.
This discovery provided high-privilege access to the domain environment, expanding their potential impact and lateral movement capabilities.
Lunar Spider employed sophisticated evasion techniques, including process injection into legitimate Windows processes such as explorer.exe, sihost.exe, and spoolsv.exe.
They established multiple persistence mechanisms, including Registry Run keys and scheduled tasks, ensuring access would survive system restarts and basic remediation attempts.
The attackers deployed multiple command and control frameworks, including Brute Ratel, Latrodectus, and Cobalt Strike beacons, creating redundant communication channels with their infrastructure.
The threat actors maintained intermittent command and control access for nearly two months. On day twenty, they exfiltrated data from file share servers using a renamed Rclone binary over FTP connections, with the process taking approximately ten hours.
No ransomware deployment was observed, suggesting the attackers prioritized data theft over destructive activities.
This campaign highlights the persistent threat posed by well-resourced cybercriminal groups and underscores the importance of robust security monitoring and rapid incident response capabilities.
Based on reporting by GBHackers.
