Hackers Exploit Legitimate Websites to Deliver BadSpace Windows Backdoor
ID: d92bb2a8-7661-52b7-a463-19c62f009013
STIX ID: report--d92bb2a8-7661-52b7-a463-19c62f009013
Feed Name: The Hacker News
Legitimate-but-compromised websites (including WordPress sites) are being used to deliver a Windows backdoor named BadSpace by overlaying pages with fake Google Chrome update pop-ups which drop either the backdoor or a JScript downloader; the multi-stage chain collects device and visitor data, contacts hard-coded C2 domains, and then deploys BadSpace which implements anti-sandbox checks, scheduled-task persistence, information harvesting, remote command execution (screenshots, cmd.exe execution, file read/write), and can remove its scheduled task. Analysis links the campaign to the JavaScript-based SocGholish/FakeUpdates ecosystem, and multiple security vendors have reported similar fake-update lures in active distribution campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
