According to the researchers at Dr. Web, they made the discovery when a customer contacted them that their Windows 10 computer had been infected.
Further analysis revealed that hackers had concealed clipper malware within the extensible firmware interface (EFI) partition in compromised versions of Windows 10 available for torrent. The primary function of clipper malware is to monitor the system clipboard for cryptocurrency wallet addresses, swiftly replacing any that it finds with addresses under the control of the attackers.
Utilising the EFI partition was a way to evade detection by traditional antivirus software, as it is not commonly scanned. The EFI partition houses essential files like the bootloader, which is executed before the operating system starts up. This means that malware stored here will be activated outside the context of the operating system and its defence tools.
Unique to this malware, was the hackers used the modified EFI partition to store malicious components to discreetly hide various applications in the system directory like droppers and injector trojans.
According to calculations by Dr. Web, malicious actors have used the clipper to steal 0.73406362 BTC and 0.07964773 ETH, which is equivalent to the sum of over £15,000. However, this is could be a fraction of the amount amassed by the cyber criminals, since the addresses identified in this investigation were from Windows 10 ISO files that were shared on popular torrent sites.
“The infiltration of malware into the EFI partition of computers as an attack vector is still very rare. Therefore, the identified case is of a great interest for information security specialists,” said the researchers at Dr. Web.
Recommended
- Roundtable | What Can Be Learned From Estonia’s Tech Success?
- Sunak: Ten Ways the UK Is the ‘Best’ for Tech Businesses
- Report: Complex Cloud Storage is Leading to Rise in Data Breaches
Hack methodology
The malware-infected Windows 10 ISOs discovered by Dr. Web contain the following apps hidden in the system directory:
- \Windows\Installer\iscsicli.exe (dropper)
- \Windows\Installer\recovery.exe (injector)
- \Windows\Installer\kd_08_5e78.dll (clipper)
When one of these compromised ISOs is installed by a user, a scheduled task is created to launch a dropper named iscsicli.exe. The dropper mounts the EFI partition as the ‘M:’ drive, and proceeds to copy the files ‘recovery.exe’ and ‘kd_08_5e78.dll’ to the C:\ drive.
The ‘recovery.exe’ file is then executed, injecting the clipper malware DLL into the ‘%WINDIR%\System32\Lsaiso.exe’ system process using a process called hollowing. Once injected, the malware will examine the system for the presence of analysis tools, to avoid detection by security researchers.
Dr. Web suggests that users download only original ISO images of operating systems and only from trusted sources, such as manufacturers’ websites. Unofficial builds can contain hidden and persistent malware.
Additionally, regular updates to security software and maintaining robust cybersecurity practices are essential for safeguarding against emerging threats in the digital landscape.





