Security Researchers Detect New Bladabindi Variant

Written byHeloise Montini
Heloise Montini

Heloise Montini is a content writer whose background in journalism make her an asset when researching and writing tech content. Also, her personal aspirations in creative writing and PC gaming make her articles on data storage and data recovery accessible for a wide audience.

Edited byLaura Pompeu
Laura Pompeu

With 10 years of experience in journalism, SEO & digital marketing, Laura Pompeu uses her skills and experience to manage (and sometimes write) content focused on technology and business strategies.

Co-written byBogdan Glushko
Bogdan Glushko

CEO at SalvageData Recovery, Bogdan Glushko has over 18 years of experience in high-security data recovery. Over the years, he's been able to help restore data after logical errors, physical failures, or even ransomware attacks, for individuals, businesses, and government agencies alike.

I think there's an issue with my storage device, but I'm not sure
Start a free evaluation

The research team at Trend Micro discovered a new variant of Bladabindi, which is a remote access tool that allows hackers to access a victim’s device through backdoor capabilities such as keylogging or distributed denial of service.

What Makes the New Bladabindi Variant Different?

According to the researchers’ findings, this new variant has been refreshed from older versions to spread without the use of files. This makes it harder for software to detect the new strain since it doesn’t take a file form as previous versions did.How Bladabindi used to work is it would infect the device. Upon doing so, it created copies of the Trojan on removable drives, meaning any device you used with the infected removable drive could be susceptible. Furthermore, the Trojan created a registry called AdobeMX so it could execute a PowerShell script for malware deployment, according to ZDNet. This is what distinguishes the new variant from its predecessors.The new variant is effective in disguising itself in many ways. For one, because the malware is in fileless form, it makes it hard for anti-virus software to detect it. And to add further concealment, the Trojan employs code protection software. Another wrinkle is the malware uses Windows’ scripting language AutoIt. This process also makes it harder for anti-malware software to detect it.[caption id="attachment_25269" align="alignnone" width="1920"]

597018-636443578723936534-16x9

Illustration by Lynda.com[/caption]

How Does Bladabindi Spread?

In previous versions, hackers deployed phishing scams to infect computers with this worm. As with other phishing campaigns the messaging included a call to action and a file attachment, whereby once the victim downloaded the file it embedded the malicious code onto their device. Once installed, the malware uses keylogging to identify everything you do on your computer. This includes capturing log in details to personal and finance websites, monitoring your browsing habits, and capturing contact data, which they could use in future phishing campaigns. And what makes the new version even trickier is the fact researchers don’t know how it spreads.

Best Practices to Minimize Data Exposure

Trend Micro states, “Users and especially business that use removable media in the workplace need to practice security hygiene. Restrict and secure the use of removable media or USB functionality, or tools like PowerShell, and proactively monitor the gateway, endpoints, networks, and servers for anomalous behaviors and indicators such as C&C communication and information theft.”It’s also a good rule of thumb for companies and personal users alike to stay on top of the latest malware trends, as this can give you insight into how hackers operate. Then, if you encounter a phishing attempt or other malware deployments, you’ll know what you’re looking for.In the meantime, it’s important to take proactive steps if data loss happens. The most effective method is to partner with a trusted team of recovery experts who have the tools and expertise to recover your files. Contact our team at SALAVAGEDATA, as we will be happy to make your case our next success story.

Share this article

Related services

These are the most commonly requested data recovery services. At our headquarters' cleanroom lab, our certified engineers conduct a thorough review of any type of physical storage device, determining if there is logical or physical damage and carefully restoring all of the lost files.ces.

External Drive Data Recovery

We recover data from both external SSD and HDD drives. Rely on certified experts to restore your important files from damaged or corrupted external drives.

/services/data-recovery/external-drive/

Hard Drive Data Recovery

Recover data from all brands of HDD, PC hard drives, and hybrid disks. Our specialists ensure fast and secure recovery for any data loss scenario.

/services/data-recovery/hard-drive/

NAS Data Recovery

Recover data from NAS devices, including RAID configurations. Our team handles all types of NAS systems and ensures data recovery with minimal downtime.

/services/data-recovery/nas/

RAID Data Recovery

Our RAID data recovery services cover RAID 0, 1, 5, 10, and other configurations. We offer expert solutions for failed, degraded, or corrupted RAID arrays.

/services/data-recovery/raid/

SAN Data Recovery

Our team specializes in handling SAN devices from leading manufacturers like Dell EMC, HP, and IBM, ensuring efficient recovery with minimal disruption to your operations.

/services/data-recovery/san/

SD Card Data Recovery

Our recovery experts specialize in restoring data from SD and memory cards. We guarantee quick recovery with a no-data, no-charge policy.

/services/data-recovery/sd-card/

SSD Data Recovery

Our data recovery experts handle all SSD data loss scenarios with advanced tools, ensuring maximum recovery with high-security protocols.

/services/data-recovery/ssd/

USB Flash Drive Data Recovery

Recover lost data from USB flash drives, regardless of the damage or brand. We offer free in-lab evaluations to assess data recovery needs.

/services/data-recovery/usb-flash-drive/

If you’re unsure about which data recovery service to choose, let our team assist you in selecting the appropriate solutions. We understand the anxiety that comes with a sudden drive failure, and we are more prompt in our actions compared to other recovery service providers.