The cybercriminals behind the RIG Exploit Kit earlier this year traded out the credential-stealer Trojan Raccoon Stealer after its lead developer was killed in the Russian invasion of Ukraine.
According to analysts with Bitdefender, the cybercrime group behind the RIG Exploit Kit was able to quickly substitute in the tried-and-true financial Trojan Dridex, which has a range of functions, including keylogging and the ability to steal screenshots.
“The move to Dridex was a strategic decision to save the operation,” Bogdan Botezatu, director, Threat Research and Reporting at Bitdefender, tells Dark Reading. “Cybercriminals running this campaign had to move to a different option or lose the money they had already invested in renting out access to the RIG EK panel. Dridex is a powerful information-stealer that, to some extent, provides similar functionality to Raccoon. Unlike Raccoon, it is still operational and can offer ‘business continuity’ to the cybercriminals behind this campaign.”
The RIG Exploit Kit lets cybercriminals quickly swap out payloads to avoid detection or in case of compromise, according to researchers at Bitdefender, making adaptability part of its product.
“This once again demonstrates that threat actors are agile and quick to adapt to change,” the analysts wrote in their report on the malware campaign.
“In order to be prepared, defenders should patch the known vulnerabilities in software used across the organization and monitor for the indicators of compromise (IOCs), Botezatu counsels. “A security solution with machine-learning capabilities can detect and block the payload at various execution stages as well.”
It’s also worth noting that Racoon is likely to make a reappearance, Botezatu notes.
“The Raccoon group has hit a temporary stop with the death of one of its operators, but we believe the team will regroup,” he says. “Usually, such groups suspend their operations when teams get arrested or when they voluntarily decide to shift to a more lucrative business. Loss of a team member is a temporary road block and we presume that they will get back online as soon as they manage to recruit a replacement.”