Phishing campaign in India deploys Blackmoon variant and SyncFuture TSM

by

A technical analysis by eSentire said an ongoing campaign is targeting Indian users with phishing emails that impersonate the Income Tax Department and deliver a multi-stage backdoor that can install a Blackmoon variant and the SyncFuture TSM remote management tool for persistent access.

KEY FACTS

  • Target Indian users via fake Income Tax Department emails
  • Delivery ZIP archive with an executable that sideloads a malicious DLL
  • Payloads Blackmoon malware variant and SyncFuture TSM RMM
  • Techniques UAC bypass, PEB process masquerading and antivirus exclusion via UI automation

The ZIP file attached to the phishing notices contains five files that are hidden except for an executable named “Inspection Document Review.exe” which is used to sideload a malicious DLL. The DLL performs anti debug checks and contacts an external server to fetch the next stage.

The next stage runs shellcode that uses a COM based technique to bypass User Account Control and modifies its own Process Environment Block to appear as the legitimate explorer.exe process. The actor retrieves a 32 bit Inno Setup installer named “180.exe” from the domain eaxwwyr[.]cn.

If Avast is present the installer changes behavior and the malware uses automated mouse simulation to add malicious files to Avast exclusions without disabling the engine. One DLL is assessed to be a variant of the Blackmoon family.

The campaign also drops a utility called “Setup.exe” that writes a file “mysetup.exe” which is assessed to be SyncFuture TSM, a commercial remote monitoring and management tool. Additional artifacts include batch scripts that change ACLs and Desktop permissions and an executable “MANC.exe” that orchestrates services and logging. Attribution to a known group is not provided.

WHY IT MATTERS

Abuse of a commercial RMM and use of persistence and antivirus evasion allow long term remote control and data monitoring on compromised endpoints, increasing the risk of sustained data theft and operational impact for affected users.