Proprietary 2016-02-01 · 121 days ·Banking Trojan, Credential Theft, Spyware, Data Theft

Ammyy download bundled Lurk

Ammyy's official download path repeatedly delivered an unsigned NSIS wrapper that installed Ammyy Admin and malware. Lurk later gave way to Fareit after arrests of suspected Lurk operators.

Story

In 2016, Kaspersky connected Lurk infections to recent Ammyy Admin downloads. The common point was not spam or exploit kits. It was the official Ammyy website, where users obtained a remote administration tool and received spyware with it.

The poisoned download was an unsigned NSIS archive. When executed, it wrote and launched two files: a digitally signed legitimate Ammyy Admin installer, aa_v3.exe, and a malicious ammyysvc.exe detected as Trojan-Spy.Win32.Lurk. The screen still looked like a normal installer.

The server-side delivery script had been modified. Kaspersky said it warned Ammyy after the first discovery and again during three February recurrences; the malicious code was removed, then returned. In early April, a modified dropper checked whether the victim belonged to a corporate network before launching Lurk.

On June 1, the payload changed from Lurk to Trojan-PSW.Win32.Fareit, the same day Russian authorities announced arrests tied to Lurk. Kaspersky read that as evidence of a market: whoever controlled the Ammyy download path could sell placement in the dropper.

Affected Artifacts

Ammyy Admin

windows installer · ammyy.com · Binary Archive
Observed
2016-02-01 to 2016-06-01
Compromised Versions
Unknown
Fixed
Not listed
Hashes
  • md5:d93b214c093a9f1e07248962aeb74fc8
  • md5:fa3f9938845ec466993a0d89517fe4bd
  • md5:c6847f43c3f55a9536ddcd34b9826c67
  • +7 more
Evidence
distribution: ammyy.com/AA_v3.exe, file: aa_v3.exe, file: ammyysvc.exe, malware: Lurk , +4 more
  • Start date is approximate; Kaspersky described discovery in early February 2016 and repeated recurrences through June 1.

Incident Context

Motive
Financial Gain Data Theft
Attribution
Group
Cause
Website Compromise
Transitive
No
Actor
Unknown cybercriminal actors

External References

Source record: proprietary/ammyy-admin/meta.yaml