No more macros? No problem, say miscreants, we'll adapt
- Reference: 1684168333
- News link: https://www.theregister.co.uk/2023/05/15/proofpoint_microsoft_macros_cybercrime/
- Source link:
"The cybercriminal ecosystem has experienced a monumental shift in activity and threat behavior over the last year in a way not previously observed by threat researchers," the security team wrote in a report
[1]PDF
just before the weekend. "Financially motivated threat actors that gain initial access via email are no longer using static, predictable attack chains, but rather dynamic, rapidly changing techniques."There were more than 700 cyber campaigns in 2021 that used Visual Basic for Applications (VBA) macros in their attacks, and almost the same number used XL4 macros, which are specific to Excel, the researchers wrote.
No macros for you
After Redmond [2]blocked both types of macros as defaults last year, [3]when downloaded from the internet , to bolster security for Office users, the number of campaigns that used either technique fell almost 66 percent and, in the first three months of this year, "macros have barely made an appearance in campaign data," Team Proofpoint claimed.
"This change is largely driven by Microsoft blocking macros by default and forcing everyone along the threat actor food chain from small crime commodity actors to the most experienced cybercriminals that enable major ransomware attacks to change the way they conduct business," according to the researchers.
[4]
Instead, miscreants are now finding fresh avenues for gaining initial access into victims' systems, a number of which we've detailed in The Register , including [5]LNK files , ISO and RAR attachments, and Excel XLL add-ins, at least until Microsoft [6]blocked those earlier this year.
[7]
[8]
Security pros had pushed Microsoft to block downloaded macros as defaults well before Redmond's move, noting their wide use by cybercriminals. Since the software vendor revisited its defaults, there's been significant change in behavior and techniques among online criminals, Proofpoint researchers wrote.
They analyzed the telemetry collected from billions of messages a day and researched data from threat campaigns between January 2021 and March 2023.
[9]
Cybercriminals distributed macro-enabled documents to targeted users and relied on social engineering techniques to convince victims that the content was important and that enabling macros would be needed to see it. If the message recipients did that, the malware payload was delivered.
Copycat attacks
They're now not only shifting away from macros but are testing other methods for gaining initial access through email and there isn't a consistent and reliable technique that is being widely adopted among miscreants.
In addition, there appears to be a follow-the-leader mentality among the crooks. One or more threat groups will adopt a new technique that within weeks and months will be used by even more miscreants. And that trend promises to continue, Proofpoint suggested.
"Some more sophisticated ecrime actors have the time and resources available to develop, iterate, and test different malware delivery techniques," the researchers wrote.
[10]Microsoft closes another door to attackers by blocking Excel XLL files from the internet
[11]Malvertising attacks are distributing .NET malware loaders
[12]Microsoft took its macros and went home, so miscreants turned to Windows LNK files
[13]Dridex malware pops back up and turns its attention to macOS
The tendency to copy what other threat groups are doing was apparent in the use of LNK files. Before April 2022, few initial access brokers (AIB) – groups that gain access into compromised systems and then sell that access to other cybercriminals, including ransomware operators – used LNK files.
But four threat groups starting using such file, including TA542 to deliver the notorious [14]Emotet malware , and soon others were doing the same until the popularity of LNK began to fade in favor of other methods.
HTML and PDF attachments get popular
Among those is HTML smuggling, whose use accelerated between June and October 2022 before dropping off and then coming back in February. Miscreants use the technique to smuggle encoded malicious script in an HTML attachment. When the attachment is opened, the web browser decodes the script, which assembles the malware on the compromised computer.
They also use PDF files that include a URL that kicks off an attack chain, which has ben in use sincee December, escpecially TA570, which is known for delivering the [15]Qbot banking trojan and info-stealing malware.
TA570 also was seen by Proofpoint experimenting with encrypting PDF attachments in a wide-ranging campaign in April. The group use encryption to make it more difficult for defenders to detect the threat, often successfully.
OneNote documents hit the scene
In December 2022, Proofpoint saw campaigns using OneNote documents to deliver the AsyncRAT remote access trojan. Microsoft's OneNote is a digital note-taking app in Microsoft 365 used to store information, plans, research, and other data. Within a few months, there were more than 120 campaigns using OneNote files.
The ongoing experimentation with new techniques is going to force threat hunters, malware analysts, and other defenders to quickly adapt, detect campaigns, and create defenses, Proofpoint researchers wrote.
[16]
"The experimentation with and regular pivoting to new payload delivery techniques by tracked threat actors, especially IABs, is vastly different from attack chains observed prior to 2022 and heralds a new normal of threat activity," the researchers wrote.
"It is unlikely there will be a single attack chain or series of techniques that remain consistent or have the same staying power as macro-enabled attachments once had." ®
Get our [17]Tech Resources
[1] https://www.proofpoint.com/sites/default/files/misc/pfpt-us-threat-research-2023-05-12-cybercrime-experimentation.pdf
[2] https://www.theregister.com/2022/07/22/microsoft-windows-vba-macros/
[3] https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805/page/2
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGKrhIWdgGLLBAL5pUDUyAAAAIY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.theregister.com/2023/01/23/threat_groups_malicious_lnk/
[6] https://www.theregister.com/2023/01/25/microsoft_excel_xll_closed/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGKrhIWdgGLLBAL5pUDUyAAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGKrhIWdgGLLBAL5pUDUyAAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGKrhIWdgGLLBAL5pUDUyAAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/01/25/microsoft_excel_xll_closed/
[11] https://www.theregister.com/2023/02/02/malvertising_malvirt_net_macros/
[12] https://www.theregister.com/2023/01/23/threat_groups_malicious_lnk/
[13] https://www.theregister.com/2023/01/06/dridex_macos_microsoft_malware/
[14] https://www.theregister.com/2023/03/09/emotet_returns_after_break/
[15] https://www.theregister.com/2022/06/09/qbot-malware-microsoft-follina/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGKrhIWdgGLLBAL5pUDUyAAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://whitepapers.theregister.com/
I'm sure that if the attack vector was a txt file saying "go to this website and download this program and run it", they'd still get some (or maybe even lots of) idiots to do it.
Microsoft's decision to block internet-sourced macros by default LAST YEAR
That shows you exactly just how much Microsoft cares about customer security. I don't know when they started with macros, but that should have been done from day one, not after, what? Two decades? It's taken that long to de-risk image viewing on the platform too, at least I assume it's safe now - you never know.
Oh sure, it has engaged in a lot of camouflage like looking for bugs at OTHER companies and blaming the victims if they did not apply patches the very millisecond they were put online (making them thus choose between alleged security or a possible self-inflicted Denial of Service due to the quality of the patches which often mirrored the questionable quality of the platform they were to be applied to), but actually improving anything?
Nah. Let's force a new UI on companies instead to keep them distracted.
And use them as beta testers.
Well they tried the.
"Are you sure?'
"This is untrusted,are you sure"
Then finally
" You've downloaded this random file from the internet. Are you sure? Yes we know you just asked, but this is probably a virus are you really fucking sure you dumb ass?
Blocking was the only answer to human stupidity.
This is why we can't have nice things
The sad reality is, inflexible business rules often mean that home grown macros are the only way to actually do your job because you're not given the proper tools to do it otherwise. I should know, because I authored one. The only way I would have ever been able to keep up with my workload was by automating a lot of the report generation. I'm sure it's only a matter of time before macros as a whole get the axe and then there's going to be a lot of people in a lot of companies all around the globe who suddenly aren't able to do their jobs because the macro they relied on for so long no longer works. And I'm sure the beancounters would rather just outsource the position to a third party company than actually provide the proper tools and support for the existing employees.
Re: This is why we can't have nice things
No powerpoint and presentations has always been a problem. It seems when you mention reports your company is on that path of having large numbers of staff giving meetings with presentations where everyone pretends they are fabulous.
It's almost like the macro stuff was SUCH an easy open door that they didn't need to care about finding obscure and new ways in.
And when it was closed, they just focused their efforts more generally to a bunch of other glaring holes all over the place.
Almost all of which, incidentally, are caused by "convenience" (e.g. opening files in associated apps by default for rendering a preview, etc.), opening untrusted files of unknown origin, and allowing things like spreadsheets to open / write to every file on your storage that your user has access to.
If only there were a way to, say, actually stop programmes executing arbitrary code with blanket access to absolutely everything a user owns or does automatically with just one click when they are in fact - plucking a random example out of the air - just a spreadsheet.