BellaCPP: Discovering a new BellaCiao variant written in C++
Dec. 20, 2024, 4:42 p.m.
Tags
External References
Description
A new C++ variant of the BellaCiao malware, dubbed BellaCPP, has been discovered by researchers. This variant shares similarities with the original .NET-based BellaCiao, including domain generation and SSH tunneling capabilities. BellaCPP was found on a machine also infected with a .NET BellaCiao sample. The malware is designed to run as a Windows service and uses XOR encryption to decrypt strings. It generates domains and checks DNS records to establish communication. The discovery highlights the importance of thorough network investigations, as attackers may deploy unknown samples to maintain persistence. The malware is attributed to the Charming Kitten threat actor with medium-to-high confidence based on similarities in functionality and infrastructure.
Date
Published: Dec. 20, 2024, 3:25 p.m.
Created: Dec. 20, 2024, 3:25 p.m.
Modified: Dec. 20, 2024, 4:42 p.m.
Indicators
e4e3f09c4257269cef6cfbebc83c8a60376ce5e547080502e3e408a3f9916218
systemupdate.info
Attack Patterns
BellaCPP
BellaCiao
Charming Kitten
T1027.001
T1021.004
T1071.004
T1569.002
T1132.001
T1573.002
T1059.001
T1547.001
T1140