{"id":36127,"date":"2019-08-14T12:39:50","date_gmt":"2019-08-14T04:39:50","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36127"},"modified":"2019-08-14T12:39:52","modified_gmt":"2019-08-14T04:39:52","slug":"sophoslabs-report-deconstructs-the-rise-and-fall-of-baldr-malware","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/08\/14\/sophoslabs-report-deconstructs-the-rise-and-fall-of-baldr-malware\/","title":{"rendered":"SophosLabs report deconstructs the rise and fall of Baldr malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos\u00a0published a detailed threat research from SophosLabs on Baldr, an information-stealer that first appeared January 2019. The report, <\/strong><a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technical-papers\/baldr-vs-the-world.pdf\"><strong>Baldr vs the World<\/strong><\/a><strong>, provides a deep dive on the popularity of the malware and its unique killchain characteristics. The in-depth research also reveals Baldr\u2019s inner workings, including cybercriminal behaviors and missteps on both the selling and buying side that potentially led to its sudden disappearance from the deep web in June. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to SophosLabs, the\npeople who developed Baldr made it to sell to entry-level cybercriminals on the\ndeep web and they, in turn, targeted PC gamers as the first set victims. Baldr\nhas since gone way beyond infecting gamers and attacks have spread to encompass\nall computer users. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Baldr, like many types of malware, uses code fragments borrowed\nfrom other malware families. However, Baldr goes to further extremes and consists\nof copied code from a <em>large number<\/em> of other malware, making it more like\na &#8220;Frankenstein&#8217;s monster of code snippets.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One reason computer users should be aware of Baldr is because it can quickly ransack a wide range of information from its victims, including saved passwords, cached data, configuration files, cookies and other files, from a wide variety of applications. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SophosLabs has tracked infections&nbsp;worldwide, including in these\ncountries:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Indonesia (more than 21% of the victim population)<strong> <\/strong><\/li><li>United States (10.52%)<\/li><li>Brazil (14.14%)<\/li><li>Russia (13.68%)<\/li><li>India (8.77%)<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Baldr heatmap from SophosLabs<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Baldr disappeared from sale in June, apparently\nfollowing an argument between the creator and the distributor.&nbsp;SophosLabs\nexpects it to re-emerge in time, perhaps with a different name.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhether\nBaldr was a flash-in-the-pan&nbsp;that quickly peaked and then&nbsp;fell victim to a squabble among cyberthieves or\nwill&nbsp;return&nbsp;as\na&nbsp;long-term threat, remains to be seen.&nbsp;However, its very existence\nis a good reminder that&nbsp;even&nbsp;stolen bits of malware code\nstitched&nbsp;together&nbsp;to create a \u2018Frankenstein-like malware\nmonster\u2019&nbsp;can be&nbsp;incredibly effective\nat bursting in, grabbing everything and rushing out again. The only way to stop\nsuch threats is with basic,&nbsp;but essential security practices&nbsp;that\ninclude using up-to-date security software,\u201d said Albert Zsigovits, a\nSophosLabs threat researcher in Hungary. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Gamers Beware<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gamers typically\nutilize much more powerful systems and are more willing to install custom\ntools, utilities, and applications from a wide variety of sources, all of which\nmake them ideal targets for malware authors. Furthermore, utilities that enable\n\u201ccheats\u201d often use common malware techniques such as DLL injection, or\nmodifying or injecting code into memory. This not only can lead to system\ninstability, but also ruins the game experience for everyone involved. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cEven though&nbsp;Baldr is currently off the deep market, it can still be used by\ncybercriminals who had previously purchased it, and is still a potential\nthreat. In general, PC gamers and all computer users should be wary of malware\nand&nbsp;take steps to protect\ntheir systems&nbsp;with security software like Sophos Home, which scans&nbsp;gaming&nbsp;software and cheats,\u201d said Zsigovits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to Protect Against Baldr Malware<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To protect against Baldr, computer users should be wary\nof phony online advertisements and videos promising \u201ctoo much\u201d \u2013 if it looks\ntoo good to be true, it probably is. Always use basic and best cybersecurity practices\nat all times on all devices. Businesses can use an enterprise security solution\nthat detects malware, such as Sophos\nIntercept X, which also protects\nagainst ransomware. Sophos Home, is ideal for scanning gaming and family computers to detect Baldr and\nother malware. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos Home\ndeploys a layered security approach, combining behavioral detection, advanced\nexploit protection, anti-virus and AI based static detection that work in\ntandem to protect gamers. Additionally, Sophos Home protects file transfers\nfrom questionable&nbsp;gaming&nbsp;sites and servers by analyzing network\ntraffic to detect malicious traffic and by scanning downloaded files in real\ntime as they are written to the file system. Combined with protection from\nphishing sites and remote management features,&nbsp;Sophos Home&nbsp;provides a well-rounded approach to protection that is an&nbsp;ideal&nbsp;security choice for gamers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lastly, all computer users need to be smart about\npasswords. Use and change complex passwords frequently, use unique,\none-of-a-kind passwords for banking and other financial online accounts and\nmonitor accounts for suspicious activity. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The in-depth research also reveals Baldr\u2019s inner workings, including cybercriminal behaviors and missteps on both the selling and buying side that potentially led to its sudden disappearance from the deep web in June. <\/p>\n","protected":false},"author":6,"featured_media":36128,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[6830,54,206],"class_list":["post-36127","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-baldr","tag-security","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36127"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36127\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/36128"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36127"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}