Information Stealing Worm - Retadup
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Worm_Retadup.A has been reportedly abusing the functionality of shortcut (LNK) files in recent attacks. The worm propagates by creating copies of itself, including shortcut files, a non-malicious executable and a malicious AutoIT script into the affected system's root directory.
The highly obfuscated malware is delivered as an executable file bundled in a ZIP file with other files of the same name but of a different extension. The ZIP also contains the encrypted data file of the actual payload. A LNK file embedded with malicious commands executes the worm.
The worm serves as a backdoor to affected systems and uses stealth functionality as well. It has its own checklist of anti-virus (AV) products, script file names and analysis, forensic and debugging tools as well as sandboxed and virtual machines. The malware will not execute if any of the above are detected.
Checks for the presence of the following LNK files relating to online payments and money transfers are performed by the worm which indicates the malware may be stealing information from those sites.
- C:\WinddowsUpdateCheck\ebay.lnk
- C:\WinddowsUpdateCheck\hamazon.lnk
- C:\WinddowsUpdateCheck\hebay.lnk
- C:\WinddowsUpdateCheck\hmoneygram.lnk
- C:\WinddowsUpdateCheck\hpaypal.lnk etc.
Research revealed that the worm attempts to steal any browser based information such as login credentials and once it has reached its target, it tries to infiltrate not just the infected system but also shared folders located within the connected local network.
It is expected that all antivirus solutions will provide updates in the near future however it is important to keep antivirus software up to date which may help with the detection of this worm.
Threat updates
| Date | Update |
|---|---|
| 25 Apr 2018 |
A new variant, Worm_Retadup.G, has been observed which is coded in the AutoHotKey scripting language and mines the Monero cryptocurrency. It creates a scheduled task to run the malicious script in the AutoHotKey interpreter, and evades detection by including random alphabetic strings within the script. |
Remediation steps
Last edited: 17 February 2020 11:32 am