Security News > 2020 > June > AcidBox Malware Uncovered Using Repurposed VirtualBox Exploit

In a report released Wednesday, Palo Alto Networks' Unit 42 sheds new light onto attacks against the popular open-source virtualization software VirtualBox that used the AcidBox malware.
The Turla Group malware, researchers said, also targeted a second DSE vulnerability tied to a signed VirtualBox driver using what would later be identified as AcidBox malware.
Researchers then traced the AcidBox malware to fresh attacks against the VirtualBox driver VBoxDrv.
Sys v1.6.2 is vulnerable and used by Turla, this new malware uses the same exploit but with a slightly newer VirtualBox version," said researchers.
Moving forward, AcidBox is a "Very rare" malware that is probably used in highly targeted attacks, researchers said.
News URL
https://threatpost.com/acidbox-malware-uncovered-using-repurposed-virtualbox-exploit/156653/
Related news
- Docker Malware Exploits Teneo Web3 Node to Earn Crypto via Fake Heartbeat Signals (source)
- ⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams (source)
- Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery (source)
- Chinese APT41 Exploits Google Calendar for Malware Command-and-Control Operations (source)
- Cybercriminals exploit AI hype to spread ransomware, malware (source)
- ⚡ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More (source)