MosaicLoader Malware
Summary
A threatening Windows malware loader that is spreading worldwide and is capable of delivering any payload to the compromised systems, virtually, has been uncovered by the infosec researchers at Bitdefender. This malware delivery platform employs a combination of several novel obfuscation techniques that make detection, analysis, and reverse-engineering of the code extremely difficult. Researchers have observed MosaicLoader deploying Facebook cookie collectors that can exfiltrate login data and credentials allowing the attackers to compromise the users account and then exploit it for a variety of malicious purposes. Through the RATs, the attackers can initiate keylogging routines, record audio from any microphone connected to the compromised device, generate images from webcams, take arbitrary screenshots and more. According to the researchers, some were created for hosting malware solely, while others are legitimate Discord URLs that point to files uploaded to a public channel.