Although after advocacy, everyone knows that downloading applications and software from official channels is the safest and most secure way, but the recent news makes people feel worried again. The security research unit found malicious viruses wrapped in the skin of well-known games in the Microsoft store. Of course, these are fake. Downloading them directly opens a backdoor in your computer. It is really difficult to predict what the backdoor will do.

Malware impersonating well-known games appears in Microsoft Store
Security research unit Check Point recently discovered that a modular malware called “Electron Bot” has secretly entered the Microsoft official store by disguising itself as dozens of well-known popular games and applications such as “Subway Surfer” and “Temple Run”, and has infected approximately 5,000 computers. The malware is a backdoor that allows unscrupulous individuals to take complete control of an infected computer, allowing it to execute commands issued remotely and deliver real-time information.

Because Electron Bot supports the registration, commenting and clicking of new accounts on social platforms, the main goals of malicious actors using Electron Bot are social media promotion and click fraud, which is achieved by taking control of social accounts on Facebook, Google, YouTube and SoundCloud. The malware is written in Electron, hence its name, and can mimic natural user browsing behavior and perform actions as if it were a real website user. This malware was first discovered in 2018, when an early variant of Electron Bot was submitted to the Microsoft Store under the name “Google Photos Album” and distributed under the fake name of Google LLC. Since then, malware developers have added several new features to their tools, such as dynamic script loading and advanced detection evasion capabilities.

Check Point researchers analyzed that the main targets of Electron Bot’s ongoing activities are the following. These functions are provided as a service to those who want to increase online profits in an opportunistic way, so malware operators can obtain indirect benefits:
- SEO Poisoning – Malware-based abandonment websites created to rank high in Google search results
- Ad clicks – Connect to a remote website in the background and click on non-viewable ads
- Social Media Account Promotion – direct traffic to specific content on social media platforms
- Online product promotions – improve ratings in your store by clicking on their ads
Its infection spread method initially involves victims downloading applications with backdoors from the Microsoft Store. Because the Microsoft Store is officially operated, everyone’s vigilance will be lowered. After launching the application, a JavaScript dropper is dynamically loaded in the background to obtain the Electron Bot payload and install it. At the next system startup, the malware will also follow the execution and connect to the C2, retrieve the remote configuration and execute any instructions issued by the remote end. Since the main script is dynamically loaded at runtime, the JS file in the computer memory is very small and looks like a harmless little sheep.

▲Run the script
▲Infection chain
Because these games containing malicious viruses detected by Check Point all have full game functions and only execute malware in the background, these games have high user ratings in the Microsoft store. For example, “Temple Endless Runner 2”, which was launched on September 6, 2021, received a near-perfect five-star rating among 92 reviews. Of course, bad actors are constantly updating their lures and using different game titles and applications to deliver malware payloads to unsuspecting victims.

Currently, the following publishers are confirmed to have launched malware:
- Lupy games
- Crazy 4 games
- Jeuxjeuxkeux games
- Akshi games
- Goo Games
- Bizzon Case
It should be emphasized here that although the current version of Electron Bot can cause catastrophic damage to an infected computer, malicious actors may modify the program to inject a second-stage payload, such as executing a RAT or ransomware. Check Point recommends that users avoid downloading apps with low review counts, and carefully check the developer and publisher details before downloading, and ensure that the app name is completely correct and does not contain confusing spellings.
Source: KOCPC Chinese