News: 1654077729

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Watch out for phishing emails that inject spyware trio

(2022/06/01)


An emailed report seemingly about a payment will, when opened in Excel on a Windows system, attempt to inject three pieces of file-less malware that steal sensitive information.

Researchers with Fortinet's FortiGuard Labs threat intelligence unit have been tracking this mailspam campaign since May, outlining how three remote access trojans (RATs) are fired into the system once the attached file is opened in Excel. From there, the malicious code will not only steal information, but can also remotely control aspects of the PC.

The first of the three pieces of malware is AveMariaRAT (also known as Warzone RAT), followed by Pandora hVCN RAT and BitRAT.

[1]

AveMariaRAT has a range of features, from stealing sensitive data to achieving privilege escalation, remote desktop control, and camera capturing. It has a keylogger, and it looks through the PC for passwords to steal from web browsers, email clients, and more.

[2]

[3]

Next up is Pandora hVNC RAT, "which is a commercial software … developed using C#, a Microsoft .Net framework," FortiGuard Labs analyst Xiaopeng Zhang detailed in a [4]write up .

"It supports features to steal credentials from some popular applications, like Chrome, Microsoft Edge, Firefox, Outlook, Foxmail, and so on. It also supports control commands to control the victim's device, such as starting a process, capturing the screenshot, manipulating the victim's mouse and keyboard, and more."

[5]

Then comes BitRAT, which has lots of commands for remotely controlling the victim's device.

The malware "is said to be a high quality and efficient RAT," according to Zhang. "It provides information collection like clipboard logger, keylogger, application credentials, Webcam logging, and Voice Recording. It has wide control commands for controlling the victim's device, including downloading and executing a file, performing remote desktop control, controlling processes and services, reverse socks, and more."

BitRAT is popular among threat actors because of its versatility and low cost – $20 for lifetime access, according to cybersecurity vendor Bitdefender. In March, it was tied to a campaign that targeted people trying to use pirated versions of Windows. The malware's payload was delivered as a Windows 10 Pro operating system license activator and was promoted on webhards – online storage services used widely in South Korea.

[6]Cops' Killer Bee stings credential-stealing scammer

[7]This Windows malware uses PowerShell to inject malicious extension into Chrome

[8]Suspected phishing email crime boss cuffed in Nigeria

[9]It's 2022 and there are still malware-laden PDFs in emails exploiting bugs from 2017

The fact that attackers can use BitRAT in multiple operations – in phishing campaigns as well as trojanized software and watering hole attacks – means it should be on network defenders' radars.

In the phishing campaign uncovered by Fortinet, an email arrives with [10]an Excel file that contains malicious macros. The entire process relies on the mark opening the file, ignoring Microsoft's warnings, and enabling the execution of macros – a bit of basic infosec hygiene on which every employee should be trained.

[11]

Phishing has been a preferred method for threat groups to get their malware into corporate networks, and only increased since the COVID-19 pandemic sent most employees home to work, outside the corporate network. [12]According to Verizon , there were 11 percent more phishing attacks in 2021 than the year before, and email security firm Tessian argued that phishing is the second most expensive cause of all data breaches in a [13]report . ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpeNJQoavnButDs9jvPwIAAAAIo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpeNJQoavnButDs9jvPwIAAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpeNJQoavnButDs9jvPwIAAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.fortinet.com/blog/threat-research/phishing-campaign-delivering-fileless-malware-part-two

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpeNJQoavnButDs9jvPwIAAAAIo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/05/31/killer_bee_interpol/

[7] https://www.theregister.com/2022/05/27/chromeloader-malware-powershell/

[8] https://www.theregister.com/2022/05/26/nigerian_phishing_arrest/

[9] https://www.theregister.com/2022/05/24/hp-pdf-phishing-malware/

[10] https://www.fortinet.com/blog/threat-research/phishing-campaign-delivering-fileless-malware

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpeNJQoavnButDs9jvPwIAAAAIo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.verizon.com/business/resources/reports/dbir/

[13] https://www.tessian.com/blog/phishing-statistics-2020/

[14] https://whitepapers.theregister.com/



So, you're not opening an email in Excel

Pascal Monett

That sentence puzzled me. Even if you're using Outlook/Office365, you open mails in Word, not in Excel.

" an email arrives with an Excel file that contains malicious macros "

That is the proper sequence of events. You get a mail from someone you've never met, download the attachment and leave your brain dead while you double-click it and ignore all warnings.

Because of course I'm going to open this attachment from some random stranger I've never met. He sent me this file, it must be important. What's the worst that could happen ?

Oh.

Re: So, you're not opening an email in Excel

BobChip

Think I'll stick with Linux and Libre Office ...................

Re: So, you're not opening an email in Excel

Anonymous Coward

.. or a Mac and LibreOffice..

Microsoft, Adobe, Google, any social media. Remove that and you don't have to fight so hard to stay safe.

Re: So, you're not opening an email in Excel

Mike 137

I'm guessing here as it's absolutely ages since I've used MS mail clients or allowed macros in Office documents, but maybe if 'attachment preview' is enabled in the mail client and macros are permitted to execute in Excel by default, the Trojan might activate without any user intervention other than opening the email itself.

If so, security is once again antithetical to convenience.

Re: So, you're not opening an email in Excel

vtcodger

"Because of course I'm going to open this attachment from some random stranger I've never met."

YOU probably won't do that unless the file content is obsfucated in some way and your OS somehow allows what appears to be a simple text file to invoke Excel. But if you have any significant number of employees, it's almost certain that a few of them can be prevented from doing so only by denying them access to email and/or Excel or by amputating their fingers.

Re: So, you're not opening an email in Excel

Handy Plough

The majority of these attacks rely on ID-107 errors. The issue here is the built-in office viewers. The ID-107 doesn’t even need to open the file directly.

Re: So, you're not opening an email in Excel

simkin

What if your job is opening similar files from customers or vendors?

National Security, if it is not just a slogan

VoiceOfTruth

It is time that governments around the world banned Excel on national security grounds.

Re: National Security, if it is not just a slogan

Alpharious

Powerpoint should also be banned, it's a dangerous neve agent that puts people to sleep and causes brain damage.

Re: National Security, if it is not just a slogan

Captain Scarlet

You can enforce this whilst I hide from the accountants foaming at the mouth whenever they can't run a macro on one of their hideous monstrosities

It's not just Excel

Version 1.0

But email is a normal hazard these days, we see infections delivered in attachments daily. This is the email environment ... it's nothing new. Here's a monastery sig when this first started years ago ... "I would like to shake the hand of the man who first decided that e-mail clients should slice, dice and run arbitrary programs. Then I'd like to stir, blend and puree his hand.

These days "security" is just a feature, not a requirement.

Re: It's not just Excel

Anonymous Coward

The I Love You malware or it might have been Melissa that was widespread around 2000 hit where I was working at the time. The down tools and don’t touch your PC message that was sent around verbally by managers was too late. Personally I didn’t have the preview window on Outlook set up but a lot of people did and therefore opened the email unintentionally. What made us laugh was the instruction from our lord and master (aka the boss) that he and his team were going to have an offsite meeting and he then marched us out of the offices. He decided we should have this meeting in a local pub and instituted a maximum drink rule. We needed to be sober if they had rid us of the bloody thing faster than we expected.

<LIM> mmmm, multitextured donuts....
<knghtbrd> LIM: with fruit filling?
<LIM> knghtbrd: chocolate cream...