On Monday, researchers at Kaspersky announced the discovery of a malware called NullMixer being distributed via websites pretending to host cracked software. NullMixer primarily works as a dropper, dropping over a dozen malicious binaries that have a multitude of functions, such as infostealers, backdoors, trojan downloaders, and cryptocurrency wallet stealers. The websites hosting NullMixer use Search Engine Optimization (SEO) poisoning to elevate their position on search engine result pages, bumping down more “legitimate” pages. The following are among the binaries dropped onto compromised systems:
- FB Stealer – Facebook Credential Harvesting
- DanaBot – Banking/Infostealer
- ColdStealer – Infostealer
- PseudoManuscrypt – Infostealer
- Raccoon Stealer – Infostealer
- Redline Stealer – Infostealer
- Vidar – Infostealer
- FormatLoader – Trojan Downloader
- GCleaner – Trojan Downloader
- LegionLoader (Satacom) – Trojan Downloader
- LgoogLoader – Trojan Downloader
- PrivateLoader – Trojan Downloader
- SgnitLoader – Trojan Downloader
- ShortLoader – Trojan Downloader
- SmokeLoader – Trojan Downloader
- C-Joker – Cryptocurrency Wallet Stealer