Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new malware campaign has been identified by cyber threat researchers at Securonix. The malware, known as OBSCURE#BAT, utilises social engineering and fake Cloudflare CAPTCHA screens to trick users into downloading malicious code disguised as legitimate software. The code within the software is heavily obfuscated to deploy rootkits, allowing it to avoid detection on compromised systems.
Impact
The impact of OBSCURE#BAT malware can have serious implications. The malware can lead to unauthorised access and control. Rootkits deployed by the malware can steal sensitive information, such as personal data and financial details. The presence of rootkits can also weaken overall system security, making it vulnerable to further attacks and exploitation. It can be difficult to remove, allowing it to continue operating undetected. Infected systems may experience performance issues, crashes, or other disruptions.
Exploitation
The OBSCURE#BAT attack uses two main methods to trick users into executing malicious batch scripts. The first method involves fake Cloudflare CAPTCHA screens on typo squatted domains. These are websites that mimic legitimate ones by using slight misspellings or variations in the URL to trick users into visiting them. The second method disguises the malware as legitimate software downloads, such as SIP software, Tor Browser, and Adobe applications. These methods initiate a sophisticated infection chain that is difficult for security tools to detect.
The initial infection begins with highly obfuscated batch scripts that execute dynamic PowerShell commands. It establishes persistence by injecting code into the Windows Registry and creating hidden scheduled tasks. The rootkit hides files, processes, and registry keys matching a specific prefix, making them invisible to standard Windows tools. To remain stealthy the files, registry entries, and processes are hidden using API hooking to make it difficult to detect.
Containment, Mitigations & Remediations
It is highly recommended to download software from verified and legitimate sources. Be vigilant against social engineering campaigns. Use services to monitor and block potential typo squatting domains. Inspect batch files before executing them and deploy robust endpoint logging for enhanced detection.
Indicators of Compromise
The malware includes several key Indicators of Compromise (IoCs). For the current IoCs, please refer to Securonix’s website.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.













