{"id":2083,"date":"2025-02-19T10:03:42","date_gmt":"2025-02-19T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/weaponized-signal-line-and-gmail-apps-delivers-malware-that-changes-system-defenses\/"},"modified":"2025-02-19T10:03:42","modified_gmt":"2025-02-19T10:03:42","slug":"weaponized-signal-line-and-gmail-apps-delivers-malware-that-changes-system-defenses","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/weaponized-signal-line-and-gmail-apps-delivers-malware-that-changes-system-defenses\/","title":{"rendered":"Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses"},"content":{"rendered":"<p>    Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyberattack campaign targeting Chinese-speaking users, malicious actors have weaponized fake versions of popular applications such as Signal, Line, and Gmail.<\/p>\n<p>These fake and weaponized apps are distributed via deceptive download pages that deliver malware capable of altering system defenses, evading detection, and exfiltrating sensitive data.<\/p>\n<p>The attackers exploit search engine manipulation to push <a href=\"https:\/\/cybersecuritynews.com\/beware-fraudulent-trading-apps-steal-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">fraudulent websites<\/a> that mimic legitimate software sources, luring unsuspecting users into downloading compromised executables.<\/p>\n<p>The malicious files are typically delivered in ZIP archives containing Windows executables. Upon execution, the malware follows a consistent pattern: extracting temporary files, injecting processes, modifying security settings, and establishing network communications.<\/p>\n<p>Researchers at Hunt.io <a href=\"https:\/\/hunt.io\/blog\/backdoored-executables-for-signal-line-gmail-target-chinese-users\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the fake Signal download page at <code>z1.xiaowu[.]pw<\/code> delivers a file named Sriguoei4.zip. Similarly, the spoofed Gmail page at <code>ggyxx.wenxinzhineng[.]top<\/code> tricks users into downloading Goongeurut.zip, which installs a fake application called \u201cGmail Notifier Pro.\u201d<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhecSeNBzMsqdXuME965NxcsscW66xfFy1OSvsdyCazJpERrN9YQUVT0PC3TkF7jDzVCyrAfnJr7uVIYbudx1wEAngSqkbXcvIvcoVJVyHYa96yyyNBnlAoFVwPU5YG9_v2xA8tFl3GLB6pHPn7BB5TsH6gl74E6WVMmPTpuiO3LZfQesPFpIIruPYwm8M\/s16000\/Fake%2520Gmail%2520login%2520page%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake Gmail login page (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Execution and System Modification<\/strong><\/h2>\n<p>Once executed, the malware employs advanced techniques to manipulate system defenses.<\/p>\n<p>One notable example involves the use of PowerShell commands to disable <a href=\"https:\/\/cybersecuritynews.com\/fake-windows-defender-alerts\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a> by excluding the entire C: drive from scanning.<\/p>\n<p>The command used is as follows:<\/p>\n<pre class=\"wp-block-code\"><code>powershell -Command \"Add-MpPreference -ExclusionPath 'C:'\"<\/code><\/pre>\n<p>This effectively renders the system vulnerable to further exploitation. The malware also drops a secondary executable, such as <em>svrnezcm.exe<\/em>, into deeply nested directories within the AppData folder:<\/p>\n<pre class=\"wp-block-code\"><code>C:UsersuserAppDataRoaming41d8a4fa27e8d998445c22590e5b2cb4562svrnezcm.exe<\/code><\/pre>\n<p>This executable spawns additional processes and communicates with command-and-control (C2) servers hosted on Alibaba infrastructure in Hong Kong.<\/p>\n<p>For example, DNS queries to <code>zhzcm.star1ine[.]com<\/code> and outbound TCP connections to <code>8.210.9[.]4<\/code> on port 45 suggest data exfiltration or remote control activities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh65YsaZeSKBG14iHI5WFlz86Ur0byCWBkABqOdkQN7eys0AXOvJE85__ws1eEwMRNr1i6rnepU0L7O5OwDI00mivOkhvE-TYJgEAjSmijLK_cC0VpLdpGY4qgsxbbbSULMpBhhRp89rIZ6b8ilu7w2dQtb9aSPN9WldRnqFxujWGXpod87gAR8xbjHRZo\/s16000\/Domain%2520Overview%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Domain Overview (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>The campaign relies on centralized infrastructure hosted at IP address <code>47.243.192[.]62<\/code>, which resolves to multiple malicious domains.<\/p>\n<p>The attackers also utilize Let\u2019s Encrypt TLS certificates to secure their <a href=\"https:\/\/cybersecuritynews.com\/china-nexus-hackers-hijack-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">spoofed websites<\/a>, adding a layer of credibility to their operations.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhGptvOGFB3oPc5Xdg19XGvGIizvpP-crTOCBUo8gTA9H-P6BPHOyYoL9qVjpFvpQfpFTGAZI8ZAQJ3q5Miwq8WOPvtXYJkSBi81thsL6iG4D0H6prjFoow4AyU_B-DqnaVEjQIc3YQjn2DsnNmWh-Zu4rfjPnCzFHszu6jOwqAowYX1VE9V6uqSAApt-g\/s16000\/Fake%2520Signal%2520Page%2520%28Source%2520-%2520Hunt.io%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake Signal Page (Source \u2013 Hunt.io)<\/figcaption><\/figure>\n<\/div>\n<p>This campaign shows the importance of verifying software sources and avoiding unofficial download sites.<\/p>\n<p>Users should remain vigilant against <a href=\"https:\/\/cybersecuritynews.com\/cloudflare-developer-domains-abused\/\" target=\"_blank\" rel=\"noreferrer noopener\">suspicious domains<\/a> and rely on trusted platforms for software installations to mitigate such threats effectively.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_feb&amp;utm_medium=article&amp;utm_campaign=ti-helps-with-alert-triage&amp;utm_content=plans&amp;utm_term=180225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/weaponized-signal-line-and-gmail-apps-delivers-malware\/\">Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/weaponized-signal-line-and-gmail-apps-delivers-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses A sophisticated cyberattack campaign targeting Chinese-speaking users, malicious actors have weaponized fake versions of popular applications such as Signal, Line, and Gmail. These fake and weaponized apps are distributed via deceptive download pages that deliver malware capable of altering system defenses, evading detection, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,258,649],"tags":[130],"class_list":["post-2083","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2083"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2083"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2083\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}