Hacker Gang DEV-0569 Found Using Google Ads To Push Ransomware Payloads

Microsoft said DEV-0569 is now pushing Royal ransomware as a post-compromise payload, besides information stealers and remote management tools.

November 22, 2022

Microsoft recently warned that a known threat actor has updated its malicious ways by incorporating Google Ads into its operations. Besides malvertising on blogs and forums, DEV-0569, a threat group Microsoft has been tracking since August 2022, is now leveraging Google Ads to distribute malware payloads, including a new ransomware strain.

Microsoft observed upgrades to DEV-0569’s campaign in October 2022, a few months after identifying malvertising through phishing links or embedded updates sent in spam emails, posted on fake forum pages and blog comments. These links and updates redirected victims to BATLOADER, a malware downloader disguised as a software installer.

Hosted on the threat actors’ domain, BATLOADER tricks users into believing it is a legitimate downloader for applications like TeamViewer, Adobe Flash Player, Zoom, and AnyDesk, and software repositories from GitHub and OneDrive.

Instead of legitimate software, DEV-0569 pushes post-compromise payloads such as information stealers or a remote management tool to achieve persistence within the target network and disable antivirus products using the open-source tool NSudo.

However, Microsoft said DEV-0569 is now distributing the relatively new Royal ransomware since at least September 2022. Moreover, the threat group is now Google Ads for covert malvertising.

As an additional defense evasion technique, DEV-0569, like the operators of IceID malware, is now employing contact forms on targeted organizations’ websites to deliver phishing links since they can help bypass email-based protections.

“Observed DEV-0569 attacks show a pattern of continuous innovation, with regular incorporation of new discovery techniques, defense evasion, and various post-compromise payloads, alongside increasing ransomware facilitation,” Microsoft noted.

“These methods allow the group to potentially reach more targets and ultimately achieve their goal of deploying various post-compromise payloads. DEV-0569 activity uses signed binaries and delivers encrypted malware payloads.”

See More: 250 U.S-Based Websites, Including News Agencies, Infected as TA569 Compromises the Ad Supply Chain

DEV-0569 Infection Chain

DEV-0569 Infection Chain | Source: Microsoft

Royal ransomware is a new strain with private operations. It doesn’t operate under a ransomware-as-a-service model, recently got its own encryption mechanism, and demands anywhere between $250,000 and over $2 million as ransom upon successfully victimizing a target.

For more details on Royal ransomware, refer to cyber threat intelligence company SecurityScorecard’s technical analysisOpens a new window .

“DEV-0569 will likely continue to rely on malvertising and phishing to deliver malware payloads,” Microsoft continued. “Since DEV-0569’s phishing scheme abuses legitimate services, organizations can also leverage mail flow rules to capture suspicious keywords or review broad exceptions, such as those related to IP ranges and domain-level allow lists.”

Let us know if you enjoyed reading this news on LinkedInOpens a new window , TwitterOpens a new window , or FacebookOpens a new window . We would love to hear from you!

Image source: Shutterstock

MORE ON CYBER THREATS

Sumeet Wadhwani
Sumeet Wadhwani

Asst. Editor, Spiceworks Ziff Davis

An earnest copywriter at heart, Sumeet is what you'd call a jack of all trades, rather techs. A self-proclaimed 'half-engineer', he dropped out of Computer Engineering to answer his creative calling pertaining to all things digital. He now writes what techies engineer. As a technology editor and writer for News and Feature articles on Spiceworks (formerly Toolbox), Sumeet covers a broad range of topics from cybersecurity, cloud, AI, emerging tech innovation, hardware, semiconductors, et al. Sumeet compounds his geopolitical interests with cartophilia and antiquarianism, not to mention the economics of current world affairs. He bleeds Blue for Chelsea and Team India! To share quotes or your inputs for stories, please get in touch on sumeet_wadhwani@swzd.com
Take me to Community
Do you still have questions? Head over to the Spiceworks Community to find answers.