Researchers at Japanese cybersecurity firm Trend Micro have identified an evasive, versatile malware dubbed “OpcJacker,” which has been circulating since mid-2022.
The threat actors behind OpcJacker disguise the malware as legitimate software, like crypto apps, to snare unsuspecting victims. Most recently, OpcJacker has been distributed via “malvertisements” for a VPN service, specifically targeting users in Iran.
“OpcJacker can steal sensitive information from an infected machine and install additional malware, which allows cybercriminals to fully control the infected machine. It uses an interesting crypter, which makes the final payload more hidden,” Jaromir Horejsi, senior cyber threat researcher at Trend Micro, told VPNOverview.
“We observed several different campaigns distributing OpcJacker. These campaigns also deliver other different malware, so we believe that this malware is used by more than one group,” he added. “We should not forget about obfuscation [evasion] and crypters, which change all the time.”
Targeting VPN Users in Iran
The latest scheme used to spread OpcJacker — observed in February 2023 — involved a phony virtual private network website, Trend Micro said. The website was not named in the analysis. However, the researchers said criminals cloned a legitimate VPN website to trick visitors and injected it with malware-laced links.
The infection chain begins with malvertisements “geofenced to users in Iran” promoting a VPN service. When users click on the ad, they’re directed to a website that checks if they’re using a VPN. If not, it redirects them to the compromised website and tricks them into downloading an OpcJacker “archive file.”
“Note that the attack will not proceed if the intended victim is using a VPN service,” the researchers said.
Before this VPN malvertisement campaign, OpcJacker — which gets its name from its “opcode” design and crypto-hijacking functions — was distributed via fake crypto apps and other phony software.
“As these campaigns deliver a few other different malware in addition to OpcJacker, we believe that they are most likely to be different pay-per-install services leveraged by OpcJacker’s operators,” the researchers explained.
The threat actors appear to have specifically targeted VPN users in Iran, as many people in the country depend on VPNs to unblock websites and anonymize their IP addresses.
OpcJacker’s Capabilities
OpcJacker’s core functions include keylogging, “taking screenshots, stealing sensitive data from browsers, loading additional [malware] modules, and replacing cryptocurrency addresses in the clipboard [when text is highlighted and copied] for hijacking purposes,” Trend Micro said.
The malware is unique because “the format resembles custom virtual machine code, where numeric hexadecimal identifiers present in the configuration file make the stealer run desired functions,” the researchers said, explaining that criminals use this design to throw off malware forensics.
While the operators of this malware appear to be motivated by financial gain, OpcJacker’s capabilities extend “beyond its initial intended use” as a malware loader or information stealer.
Researchers believe OpcJacker may still be under development and testing after discovering snippets of code within OpcJacker named “test” and “test_installs,” presumably meaning that the malware is still being fine-tuned and could be used in other campaigns.
“Given its unique design combined with a variety of VM-like [virtual machine] functionalities, it’s possible that the malware could prove to be popular with threat actors, and therefore could see use in future threat campaigns,” Trend Micro said.
How to Stop OpcJacker
According to Horejsi, a good antivirus can stop OpcJacker if configured properly.
“Yes, if proper detections/rules are added to the antimalware solution, then, of course, malware can be stopped,” he said.
We recommend protecting your systems from sophisticated malware with one of our top-rated antivirus solutions, like Norton’s 360 suite. A good antivirus tool will notify you when you visit a malicious website and quarantine malware threats.
For additional security, we recommend encrypting your internet traffic with a trustworthy VPN, such as NordVPN, which also offers malware threat detection capabilities.
