Site navigation

New Exploit Uses Windows 10 Torrents to Distribute Malware

Michael Edgar

,

Exploit malware EFI partition
Cybersecurity researchers have uncovered a new hacker exploit, which uses Windows 10 torrents to distribute malware.

According to the researchers at Dr. Web, they made the discovery when a customer contacted them that their Windows 10 computer had been infected.

Further analysis revealed that hackers had concealed clipper malware within the extensible firmware interface (EFI) partition in compromised versions of Windows 10 available for torrent. The primary function of clipper malware is to monitor the system clipboard for cryptocurrency wallet addresses, swiftly replacing any that it finds with addresses under the control of the attackers. 

Utilising the EFI partition was a way to evade detection by traditional antivirus software, as it is not commonly scanned. The EFI partition houses essential files like the bootloader, which is executed before the operating  system starts up. This means that malware stored here will be activated outside the context of the operating system and its defence tools.

Unique to this malware, was the hackers used the modified EFI partition to store malicious components to discreetly hide various applications in the system directory like droppers and injector trojans. 

According to calculations by Dr. Web, malicious actors have used the clipper to steal 0.73406362 BTC and 0.07964773 ETH, which is equivalent to the sum of over £15,000. However, this is could be a fraction of the amount amassed by the cyber criminals, since the addresses identified in this investigation were from Windows 10 ISO files that were shared on popular torrent sites. 

“The infiltration of malware into the EFI partition of computers as an attack vector is still very rare. Therefore, the identified case is of a great interest for information security specialists,” said the researchers at Dr. Web. 


Recommended


Hack methodology

The malware-infected Windows 10 ISOs discovered by Dr. Web contain the following apps hidden in the system directory:

  • \Windows\Installer\iscsicli.exe (dropper) 
  • \Windows\Installer\recovery.exe (injector) 
  • \Windows\Installer\kd_08_5e78.dll (clipper)

When one of these compromised ISOs is installed by a user, a scheduled task is created to launch a dropper named iscsicli.exe. The dropper mounts the EFI partition as the ‘M:’ drive, and proceeds to copy the files ‘recovery.exe’ and ‘kd_08_5e78.dll’ to the C:\ drive. 

The ‘recovery.exe’ file is then executed, injecting the clipper malware DLL into the ‘%WINDIR%\System32\Lsaiso.exe’ system process using a process called hollowing. Once injected, the malware will examine the system for the presence of analysis tools, to avoid detection by security researchers.

Dr. Web suggests that users download only original ISO images of operating systems and only from trusted sources, such as manufacturers’ websites. Unofficial builds can contain hidden and persistent malware.

Additionally, regular updates to security software and maintaining robust cybersecurity practices are essential for safeguarding against emerging threats in the digital landscape.

Michael Edgar

Staff Writer, DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences