Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware
Cybercriminals are utilizing the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware .
Cybercriminals are utilizing the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware .
The threat actors exploited news surrounding Maduro’s arrest on January 3, 2025, to execute malicious campaigns effectively.
The attack likely commences with a spear-phishing email containing a zip archive titled "US now deciding what's next for Venezuela.zip".
Inside, recipients find an executable file labeled "Maduro to be taken to New York.exe" along with a malicious dynamic-link library named "kugou.dll".
The executable is a legitimate KuGou binary, which has been weaponized through DLL hijacking to load the malicious library, as reported by Darktrace security researchers .
Once executed, the malware creates a directory at C:\ProgramData\Technology360NB and duplicates itself, renaming the files.
Cybercriminals are utilizing the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware .
It establishes persistence by adding a registry key at "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Lite360" to execute automatically at system startup.
The malware then displays a dialog box prompting users to restart their computer, which activates the malicious payload .
Upon system restart, the malware initiates regular encrypted connections to a command-and-control server at 172.81.60[.]97 on port 443.
These periodic connections enable the malware to receive instructions and configurations from the attackers.
The campaign bears similarities to previous operations by Mustang Panda, a Chinese threat group known for exploiting current events. However, researchers note insufficient evidence to attribute this activity to any specific group definitively.
This incident underscores the ongoing threat of geopolitical-themed phishing campaigns .
Organizations and individuals should exercise caution when opening email attachments, especially those referencing breaking news or world events.
172.81.60[.]97 8f81ce8ca6cdbc7d7eb10f4da5f470c6 – US now deciding what's next for Venezuela.zip 722bcd4b14aac3395f8a073050b9a578 – Maduro to be taken to New York.exe aea6f6edbbbb0ab0f22568dcb503d731 – kugou.dll
For more updates, follow us on Google News , LinkedIn , and X .
Based on reporting by Cyber Security News.
