'Fully undetectable' Windows backdoor gets detected
- Reference: 1666124048
- News link: https://www.theregister.co.uk/2022/10/18/fully_undetectable_windows_powershell_backdoor/
- Source link:
More significantly, the malware may backdoor your Windows system by masquerading as part of the update process.
Tomer Bar, director of security research at SafeBreach, explains in an [1]advisory that the software nasty and associated command-and-control (C2) backend appear to have been developed by a competent unknown miscreant – though one not savvy enough to avoid mistakes that allowed SafeBreach researchers to figure out what was going on, natch.
[2]
"The attack starts with a malicious Word document, which includes a macro that launches an unknown PowerShell script," said Bar. "The name of the Word document is ' [3]Apply Form[.]docm .'"
[4]
[5]
According to Bar, the malicious Word document was uploaded from Jordan on August 25, 2022.
The file appears to have been part of a phishing campaign designed to look like a LinkedIn-based job offer, in order to entice victims to open it. The mark would have to allow the macro in the Word document to run for an infection to be successful.
[6]
Asked to provide more details, a SafeBreach spokesperson said, "We don't have additional information about the targets, but we believe that this is a sophisticated targeted attack, possibly related to the phishing attempts targeted at job seekers."
About 100 victims are said to have been affected.
[7]Steganography alert: Backdoor spyware stashed in Microsoft logo
[8]Check out this Android spyware, says Microsoft, the home of a gazillion Windows flaws
[9]China-linked spies used six backdoors to steal info from defense, industrial enterprise orgs
[10]Symbiote Linux malware spotted – and infections are 'very hard to detect'
"The macro drops updater.vbs , creates a scheduled task pretending to be part of a Windows update, which will execute the updater.vbs script from a fake update folder under '%appdata%\local\Microsoft\Windows ," explained Bar.
The updater.vbs script then runs a PowerShell script that opens a remote-control backdoor on the box.
According to Bar, prior to executing the scheduled task, the malware creates two PowerShell scripts, Script.ps1 and Temp.ps1 . Their content gets obfuscated and stored in text boxes within the Word file and gets saved to the fake update directory. As such, the scripts don't get detected in VirusTotal.
[11]
Script.ps1 calls out to the C2 server to assign a victim ID number and to fetch commands to execute. It runs the Temp.ps1 script, which will store information or execute PowerShell commands depending on the parameters passed by the initial script.
According to Bar, the attacker messed up by issuing victim identifiers in a predictable sequence. This allowed the security researchers to develop a script that presented each victim's identifier to the backend system, so they could record the interactions with the C2 server in a packet capture. Thereafter they were able to use a second tool to extract the encrypted commands from the captured packets and decipher what the malware was doing.
Microsoft recently changed the default behavior of Office apps [12]to block macros in files downloaded from the internet, something previously possible through a Trust Center policy.
We asked SafeBreach whether this might offer any protection.
"Yes, if macros are disabled, this attack vector won't work," a spokesperson said. "But if the threat actor uses a different attack vector (exploits for example instead of macros), the FUD PowerShell malware would work and spy on the victim." ®
Get our [13]Tech Resources
[1] https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y08h9Kw-CtkjJrrap7Y7JwAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.virustotal.com/gui/search/name%253A%2522Apply%2520Form.docm%2522
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y08h9Kw-CtkjJrrap7Y7JwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y08h9Kw-CtkjJrrap7Y7JwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y08h9Kw-CtkjJrrap7Y7JwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/10/02/witchetty_windows_logo_spyware/
[8] https://www.theregister.com/2022/09/22/microsoft_android_spyware_endpoint/
[9] https://www.theregister.com/2022/08/09/china_apt_kaspersky/
[10] https://www.theregister.com/2022/06/10/symbiote_linux_malware/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y08h9Kw-CtkjJrrap7Y7JwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://learn.microsoft.com/en-us/deployoffice/security/internet-macros-blocked
[13] https://whitepapers.theregister.com/
And the wheel of reincarnation strikes again...
And mainly because using the OLE Automation hooks are hard and require additional time and effort to build to.
And as we can all see, no one at Adobe looked at Microsoft's problem with it and said "hey, let's embed a scripting engine into our PDF viewer which will let miscreats do the same exact thing !!!"
To be fair
Windows didn't support networking back then, so the only attack vector was sneakernet.
The real crime wasn't adding that functionality 30 years ago, it was maintaining their support for it once it became known what a big problem it was. They could have and should have deprecated it long ago.
Re: To be fair
Not natively, AFAIK, but there had long been third party networking (such as Netware) and even third party TCP/IP stacks had been around for a few years.
Once that happened "You know what would be great? If we could embed executable code in a web page." has no excuse.
Actually, as those scripts are written, the actual powershell code could be hidden in any file. .PNG, .JPEG, .ODF and so on. And since many file formats are actually renamed zip files (hello ODF DOCX JAR etc etc) you can include whatever in such a zip file.
The word document is just the easiest way since you cannot fix dumb. Including dumb implementation from M$, making the "activate script" button huge, but the save "don't" button small. But what to expect from the UI designers of Windows 8.0 and Windows 11...
In 1992: "You know what would be great? If we could embed executable code in a Word document."