Home FakeBat Loader Malware Becomes #1 Cyberthreat in 2024, Continues to Spread through Drive-by Downloads
News

FakeBat Loader Malware Becomes #1 Cyberthreat in 2024, Continues to Spread through Drive-by Downloads

Krishi Chowdhary Journalist Author expertise
Disclosure
Disclosure
In our content, we occasionally include affiliate links. Should you click on these links, we may earn a commission, though this incurs no additional cost to you. Your use of this website signifies your acceptance of our terms and conditions as well as our privacy policy.
  • Sekoia Threat Detection & Research (TDR) conducted research on FakeBat—a malicious software loader and dropper—and found it to be one of the biggest cyberthreats of the first half of 2024.
  • It targets victims by either imitating a legitimate website, compromising a website, or through social engineering schemes on social networks.
  • The worst part is that this malware is being distributed as a loader-as-a-service (LaaS) subscription model, meaning more cybercriminals, including the entry-level ones, are gaining access to it.

FakeBat Loader Malware Becomes #1 Cyberthreat in 2024, Continues to Spread through Drive-by-Download Attacks

FakeBat, which is also known as PaykLoader and EugenLoader, has emerged to be one of the most dangerous cyberthreats in the first half of 2024.

The campaign involves drive-by downloads, which is a technique that involves malvertising, SEO poisoning, and inserting malicious code into websites that have been compromised. Users are then tricked into downloading the malware in the disguise of a fake update or app.

Read more: Biggest cyberattacks of 2023 and what caused them

About FakeBat and Its Growing Terror

Sekoia Threat Detection & Research (TDR) conducted research and found that throughout 2024, there have been multiple FakeBat distribution campaigns. This cyberthreat’s latest victims include AnyDesk and Google Chrome.

It tricks users via three methods:

  • By imitating a real website,
  • By compromising an actual legit website, or
  • Through social engineering schemes on social networks

Then, it downloads the next-stage payload, such as Lumma, IcedID, SmokeLoader, RedLine, SectopRAT, and Ursni.

FakeBat’s servers are also believed to filter traffic based on location, IP address, and user-agent value so that they can target a specific audience.

During research, Sekoia also found that certain domains linked to FakeBat’s command-and-control (C2) servers, including 756-ads-info[.]site, 3010cars[.]top and 0212top[.]online, are often registered under concealed or misleading details regarding ownership.

These domains are the main drivers behind malware distribution. Moreover, these distribution strategies are so diverse that FakeBat has managed to evade detection for a really long time.

What’s worse is that FakeBat is being offered to other cybercriminals as a loader-as-a-service (LaaS) subscription model on dark web forums designed by a Russia-based threat actor called Eugenfest (aka Payk_34).

Unfortunately, using the loader is quite simple, too. It has templates that can be used by hackers to generate builds, which would help them compromise legit websites as well as monitor their installations through an administration panel.

The service is available at $1,000 per week (or $2,500 per month) for the MSI format (MSI is its previous version) and $1,500 per week (or $4,000 per month) for the MSIX format (the newest version). Furthermore, a combination of MSI and the signature package is available at $1,800 per week (or $5,000 per month).

The Tech Report - Editorial ProcessOur Editorial Process

The Tech Report editorial policy is centered on providing helpful, accurate content that offers real value to our readers. We only work with experienced writers who have specific knowledge in the topics they cover, including latest developments in technology, online privacy, cryptocurrencies, software, and more. Our editorial policy ensures that each topic is researched and curated by our in-house editors. We maintain rigorous journalistic standards, and every article is 100% written by real authors.

Question & Answers (0)

Have a question? Our panel of experts will answer your queries. Post your Question

Leave a Reply

Write a Review

Your email address will not be published. Required fields are marked *

Krishi Chowdhary Journalist

Krishi Chowdhary Journalist

Krishi is an eager Tech Journalist and content writer for both B2B and B2C, with a focus on making the process of purchasing software easier for businesses and enhancing their online presence and SEO.

Krishi has a special skill set in writing about technology news, creating educational content on customer relationship management (CRM) software, and recommending project management tools that can help small businesses increase their revenue.

Alongside his writing and blogging work, Krishi's other hobbies include studying the financial markets and cricket.

Latest News

BlackRock Eyeing Private Market Indexing After Preqin Acquisition
News

Blackrock Eyeing Private Market Indexing after Preqin Acquisition

Content Moderation Doesn't Violate First Amendment, says SC
News

Supreme Court Rules Content Moderation Doesn’t Violate First Amendment

On Monday, the Supreme Court ruled that content moderation falls under the First Amendment rights of social media companies – a partial victory for the companies. The decision came from...

Dogecoin Loses Ground: Can the Original Meme Coin Bounce Back?
Crypto News

Dogecoin Loses Ground: Can the Meme Coin Bounce Back?

Dogecoin’s price has taken a nosedive, shaking its position among top cryptocurrencies. Given the bearish market condition, Dogecoin’s future seems uncertain as experts predict further declines in the coming days. This...

Ether Options Market Bullish Ahead of Spot ETF Launch, Mirroring Pre-spot BTC ETF Trend
Crypto News

Ethereum Options Market Bullish Ahead of Spot ETF Launch, Mirroring Pre-spot BTC ETF Trend

Fidelity and Sygnum Strike Deal with Chainlink to Transform Tokenized Asset Data
Crypto News

Fidelity and Sygnum Strike Deal with Chainlink to Transform Tokenized Asset Data

Mantra Plans Tokenization of $500M Real Estate Assets for the UAE Developer MAG Group
Crypto News

Mantra Plans Tokenization of $500M Real Estate Assets for the UAE Developer MAG Group

Canadians Show Strong Preference for Cash, Crypto Struggles to Grasp Attention
Crypto News

Canadians Show Strong Preference for Cash, Crypto Struggles to Gain Traction