The cybercriminal gang behind the Gootkit malware has resurfaced recently in a malicious campaign targeting Australian healthcare organisations.
Researchers first discovered Gootkit as a banking Trojan in 2014. According to recent reports, the company’s “operators now seem to provide access as a service, with the odd feature of running infection campaigns specifically targeted at certain geographic areas.”
Many people believed the Gootkit malware was defeated in 2019 when a security researcher discovered two publicly accessible MongoDB instances that seemed to be a part of the Gootkit network. However, this belief was disproved in 2020 when reports surfaced of a campaign allegedly targeting German victims for REvil ransomware infection.
Trend Micro researchers claim to have discovered Gootkit operators using deceptive SEO strategies to entice new victims by searching Google for terms like “hospital,” “health,” “medical,” and “enterprise agreement,” along with Australian city names.
When a victim clicks on a site that appears to give a sample contract for a midwife, the Gootkit operators will require them to download a zip file.
Malicious JavaScript was present in the zip file. Still, Gootkit once more added a unique twist to the standard hacking script by delaying the execution of the second stage of infection for several hours or even days. This latency “clearly differentiates the first infectious stage from the second stage.”
The second step required downloading a file from a command-and-control server that mimicked the VLC Media Player that loads a Cobalt Strike-related module that establishes persistence.
Despite not claiming that the Gootkit campaign was responsible for the Medibank attack, Trend Micro notes that the “recent campaign might remind us of this incident.”
This campaign is alarming as malicious actors increasingly focus their efforts on the healthcare industry, which is often ill-prepared to defend against such attacks.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...