Talos Takes
Every two weeks, host Amy Ciminnisi brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic. We cover everything from breaking news to attacker trends and emerging threats.
Talos Takes
ClickFix, EtherHiding, and the rise of malicious code in the blockchain
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure.
Vanja walks us through how threat actors are repurposing legitimate user behaviors — like solving CAPTCHAs — to gain unauthorized access, and how they utilize blockchain smart contracts as bulletproof storage for malicious code. We also explore the divergence in final payloads, ranging from remote access tools to crypto-stealing malware. Tune in for actionable behavioral patterns that your security teams can monitor to detect these incidents before they progress.
Vanja's blog: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
Welcome to the Talos Takes Podcast, where we discuss Talos' latest research and security news. This podcast is for everyone, from the C suite to the front lines.
Amy CiminnisiHello and welcome to Talos Takes. I'm Amy Ciminnisi. Today we're looking at a fascinating infection chain that has been targeting organizations with a mix of legitimate tools and decentralized infrastructure. It starts with a simple web dab execution, but as our guest Vanja Svajcer discovered, that initial alert was the tip of the iceberg. There is ClickFix social engineering and the use of BNB smart chain to host malicious code, going on. This campaign uses resilient and harder-to-track tactics. So I'm joined by Vanja today to break down how this infection chain works, why it's so effective, and what security teams can do to spot these patterns before everything hits their network. Vanja, welcome.
Vanja SvajcerThank you, Amy. It's great to be back and talking with the Talos Takes.
Amy CiminnisiYeah, absolutely. Your report starts with a fairly specific observation uh uh at a Ukrainian governmental organization. Can you take us back to that initial moment? How did that telemetry stand out to you? And what were the first clues that kind of pointed toward a broader operation?
Vanja SvajcerYeah, so so what we do in in our daily research, we're trying to monitor all of the Cisco Talas customers, right? But when it comes to a government organization, specifically if it's a kind of Ukrainian government organization, in if and if we see some suspicious command line being executed, certainly we will investigate, right? And uh so when I when I started looking into it, it was pretty obvious that this is not a legitimate command line call, right? So you have like a web dev call for the uh uh web service to uh download a file from a remote share um which is named uh verification.google. Um and so so this is really an unusual name, uh, first of all. And then and then you see the call to run it with run DLL32. Um it's a kind of a typical sign that something is wrong here and an indicator of a malicious activity.
Amy CiminnisiYeah, yeah. Um and this chain relies pretty heavily on ClickFix tactics that impersonate a Google CAPTCHA, right? So given that users are being instructed to perform the attack themselves by pasting these commands into the run dialogue, um, what do you think are the biggest challenges for organizations who are like trying to train users against this kind of human-centric, you know, deception?
Vanja SvajcerYeah, I think when when clickfix appeared, I was like, ha ha ha, nobody will fall for it, right? But obviously I was very wrong because these days clickfix is de facto the most the most common type of like infection vector. And so so the the the the bad guys, the threat actors have perfected how they create these fake capture verification uh uh pages, like whether they look to come from Google or from Cloudflare or like anything, because you know, we are now very much used to somehow um having to certify that this is a human behind the keyboard. And so most of these websites are trying to at least limit the activity of bots on their sites, and so we often see these, you know, show that you are actually human. And and and this exact fact is used by threat actors to kind of lure us into believing that what we are seeing is just a traditional normal kind of uh CAPTCHA operation or you know, uh proving that that we are not robots. And uh so so so you could you could say that it's so much similar to a legitimate um activity that for somebody, for especially for users who are not technical users, we need to invest a little bit more in um education, but also from the technical side, uh we need to be able to detect when the um activities such as that, like copying potentially suspicious code or a URL to the clipboard and then pasting it in uh in the Windows Run prompt so that it's run. Um so how it's detected is a different question because you know of course it's it's not obvious we need to connect different events from the download to uh from from the visiting the page to the actual copying and pasting some of the code. So yeah, there is there is there are technical and there are kind of organizational issues around that. And I and I'm not surprised that that ClickFix continued in the end. Like I said, I was quite skeptical at the beginning, but I I was proved to be very wrong. So yeah.
Amy CiminnisiI mean, it's such it like it's something that so many people do on autopilot, you know, they don't pay attention to it. But I mean this particular prompt was I mean, I I don't know, maybe I'm slightly more tech technically literate than the average person, but like it was a little bit more obvious than your usual click, click these images.
Vanja SvajcerIt's a little bit more obvious, but then again, it also had the Google sign and and the kind of the standard logos where you could just if you're like you said, an autopilot, then you just do whatever it's you're instructed to do because you probably go, okay, I don't have to click on images, but now they ask me to prove that I'm a human by copying and pasting something in and entering that in this window. Yeah. Yeah. Unfortunately, in the background you see that bad thing starts happening. And and certainly in this case, we we we have seen the that the the kind of access to remote share happens followed by launching this remote uh uh code from uh a dynamic loading library, which then started the whole infection chain.
Amy CiminnisiRight. Uh so let's talk about uh BNB Smart Chain. Uh this campaign uses it uh specifically contract their contracts um as storage for malicious JavaScript. Um this is a technique you said is known as ether hiding. First, can you kind of explain how this works?
Vanja SvajcerWell, yeah. Um so usually, you know, to conduct threat operation or or like threat actor operation, they need to have some tools which they will install on the target systems, but then usually they need some kind of infrastructure. And and if you set your infrastructure with the standard domain name or IP address, those are the signs which can be very easily detected uh by kind of endpoint security software on or any kind of protection you have, like if you have in-depth defense, then you you'll be able to find those. Um and and if you find them, you can also go to the service provider and maybe ask to for that code to be taken down. With blockchains or the smart chains, we we we kind of have different situations. Once when the transaction or the contract is already on the blockchain, it's very easy to it's very easy to see, but it's very difficult to remove. So, in in a way, the blockchain became for many of these threat actors from also like commodity-based threat actors, but also sometimes more advanced threat actors, kind of like a bulletproof hosting platform, where even if it's visible, it's will still remain on. So um, so the the the the concept of ether hiding is just a technique where threat actors leverage public smart contract blockchains uh as kind of repositories for either uh command and control domain repository or the actual malicious payload, they can also store small small snippets, snippets of code, which we we've actually seen uh one and the other in some parts of the infection chain. I think it's it's worth saying that from the verification Google uh point, uh we haven't seen the ether hiding. But um when you when we came back to try to find out the whole infection chain, we really didn't know whether it was a ClickFix or not. So what we just tried to find out whether we had something similar in our repositories, and then then we identify another whole chain, which kind of indicated um and uh that it started with uh with a ClickFix prompt um that went to the BMB smart chain that then kind of caused the the web dev transaction to happen and to the malicious code to be launched on the system. So so that's why within the blog post we actually compared two infection chains, but um they are kind of related, but not necessarily by the same threat actor.
Amy CiminnisiOh, okay. So that that was actually kind of my next question. So the initial delivery chain is similar, but then the payloads kind of diverge, right? So one branch you said deploys um a Zig-based crypto sealer, um, and the other installs NetSupport Manager. Um, so for me, when I read this, a few thoughts went into my head. You know, I was curious, like, okay, is this like a malware as a service model, or is it a single operator like testing different tools for different environments? So like I'm curious kind of what what you think about that and um yeah, what your thoughts are.
Vanja SvajcerYeah, I think I think like the Amateira Steeler kind of evolved from a Steeler that was called ACR or a Russian Steeler. It was advertised on like dark web and some other kind of underground forums. Um and and I think it's it kind of points to this sort of malware as a service model when we have that operator of the infrastructure, and that operator will have like different campaigns which are then you know used by some affiliates. I I don't know if I don't know if we have this kind of uh definite proof that it's it's like that, but it's certainly based on those two infection chains, and um you know to be honest, those are not the two only two infection chains I was able to find. There are like many, and and if you know, if like you're if you're like a threat researcher, or if you're interested in that, you can go to some of the open source repositories and you will be able to find more. But but the the second one was like a complete, and so I just use it to illustrate what likely happened in the first one as well. And and here we have like two very let's say distinct uh final payloads. So, what Amatera uh allows you to do, first of all, Amatera has in its own um built-in functionality for stealing like user credential, cryptocurrency details, and so on. That's kind of by default. It's it's very well um I would say programmed, it's it's very well developed. But one of the additional things, um, first of all, when you when you launch it, it goes to the command and control server, and then and then it will it can have a uh a configuration within its own file, but often that configuration is downloaded and then decrypted and only loaded in memory. And as a part of that, it's like a huge JSON-based object. And and and as a part of that, there is a command LD, I think, and the LD allows uh the threat actor to specify the secondary payload. And secondary payload can be a zip file, it can be an executable, it can be a DLL, it can even be shellcode, which is only seen in memory. And so this is where we've seen that that these two chains diverge. Um the the the first chain, the verification.google chain used um kind of a um remote access tool, which is kind of in um kind of a gray, let's say, area, because it is a legitimate tool. However, uh it's been misused by many uh threat actors, and it seems that some of the kind of licenses have been leaked. It's called Net Support Manager. Um, and although it could be used for legitimate purposes, in this case, it was quite clear that that the dedicated C2 server was based in in Russia for it. Uh or it's not exactly the C2 server, but it's a gateway which is used for communicating to the threat actor. So uh and in the second case we had something different. We had like an improved uh crypto stealing component in Zig CryptoStealer, uh, which was installed together with uh kind of an EDR killer functionality in uh uh bring your own kind of vulnerable driver, uh which which was like standard thing to be done by some of these threat actors. Disable security software and then conduct your operation, which in that case was really clearly focused on uh stealing information and cryptocurrency details. On the side of the verification.google, you know, we have Net Support Manager that indicates more that we want to obtain and um keep being able to uh connect to the targeted and infected systems through this kind of remote access tool.
Amy CiminnisiGot it. So just like completely different motivations. For practitioners who are listening to this, who want to defend their networks against these specific infection chains, beyond the known IOCs that we have in the blog, what uh behavioral patterns should they be looking for?
Vanja SvajcerYeah, so of course you you can always have like your IOCs and things like that. But I I think you need to first of all look at what's your kind of attack surface within your organization. And you know, for example, if you're not using the web distributed authoring and versioning, web dev, you know, you can try to disable it on your system. So there is some kind of proactive measures you can do. In is a specific case for this specific infection chain. But overall, you know, when you when you think about like protecting, you you need to be aware of these kind of techniques. So one of them is kind of web dev, the second is launching run dl32 um by referencing uh a file with with a um with an export number or ordinal rather than the export name. That's that's quite unusual for a legitimate uh usage of DLLs with with the run DLL uh program. Um, you know, if if in the case where the vulnerable driver was loaded, you can monitor some of the events, such as loading of the driver. You know, when you find a driver which is kind of there and potentially vulnerable, that's a kind of red flag for your EDR service. And and overall, you need to, of course, uh have the kind of good logging infrastructure, centralized logging, where when things like that happen, you can always have to be able to go back in time to first of all identify all the components and the TTPs by the threat actors. Uh because you know, let's let's face it, you you won't be able to prevent every time like any kind of attacks. Of course, if you if you have your defense in depth, yes, great. Um the the good things with these things, uh such as the two-chain that we documented, is that that even if they use some, let's say, semi-advanced tactics, they they are pretty noisy, right? Because you know, we see indicators, web dab, run DLL with the weird uh name of the DLL, um call by ordinal, vulnerable driver load, some network communications. So so you you be have to be able to look at at some of the um sequences of events in the context of like a single possible incident. So you know, there's no one thing, but you just need to be aware that some things like that can can happen. Also, you you when you see that um the traffic, you're not, for example, your organization or a business or a government organization, and suddenly you have some kind of uh suspicious or weird Web3 blockchain looking calls or or communications, and you you know that it shouldn't be used, then you know it could be a good indicator that something is wrong. Certainly something to be investigated in your SOC.
Amy CiminnisiRight. Yes. And of course, you know, weird code being run by users who normally wouldn't have to do any of that, like people in the business development department, people who wouldn't really know how to do any of that as well.
Vanja SvajcerAbsolutely. I mean, we often say that identity is one of the main kind of ways how you can use for detecting because it's not just like what's going on, but who is conducting these operations.
Amy CiminnisiYeah. All right. Well, thanks so much for joining me, Vanja. Really appreciate it.
Vanja SvajcerThank you. It's been great talking to you.
Amy CiminnisiWonderful. Listeners, I will put Vanja's blog in the show notes. So please do check that out for more details. If you're interested in staying up to date with our research, you can check out our blog at blog.talosintelligence.com. And also, shameless plug, you can subscribe to our newsletter there too. We'll see you again in two weeks with a new episode. And until then, stay safe out there.