PhishingMalware

Zillow Impersonation Campaign Delivers DarkCloud Malware

The NJCCIC observed a phishing campaign attempting to distribute DarkCloud malware by impersonating Zillow. DarkCloud is an information stealer that can collect and exfiltrate browser data, record keystrokes, and replace cryptocurrency wallets on infected devices. It is typically spread through phishing emails. Messages in the campaign spoof Zillow sender mailboxes, pretending to be from “Zillow Rental Manager” with the sender address noreply[@]zillow[.]com. The messages claim to handle various administrative tasks related to Zillow rental properties.

Phishing email impersonating Zillow Rental Manager with an Adobe PDF attachment.
Phishing email impersonating Zillow Rental Manager with an Adobe PDF attachment.

The email includes an Adobe PDF attachment with an embedded URL that purportedly allows the target to view the document. If clicked, the URL triggers the download and execution of DarkCloud. The malware installs itself to autorun at Windows startup by creating a Windows Registry key.

Fake Adobe Document Cloud page prompting the target to view the document online.
Fake Adobe Document Cloud page prompting the target to view the document online.

Registry key for autorun: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DOC
File path where DarkCloud installs itself: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DOC.exe

Recommendations

  • Avoid clicking links and opening attachments in unsolicited emails.
  • Confirm requests from senders via contact information obtained from verified and official sources.
  • Maintain robust and up-to-date endpoint detection tools on every endpoint.
  • Consider leveraging behavior-based detection tools rather than signature-based tools.
  • Review the Don’t Take the Bait! Phishing and Other Social Engineering Attacks NJCCIC product for more information on common phishing and social engineering attacks.