Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security Alert: New Spear Phishing Campaign Operated by the MuddyWater Group
#1
Exclamation 
Quote:
[Image: heimdal-logo.svg]

In which malicious Powershell payload is used to spread malware

You probably heard about the hacking group known as “MuddyWater” which was behind previous spam campaigns targeting a wide range of industries and institutions in several countries across the Middle East, Europe, and the US.

Spotted for the first time in 2017, when the group hit the Saudi Government, future spam campaigns discovered by security researchers were also linked to the same group.

It appears that the authors of the MuddyWater group aren’t slowing down these attacks and continue to be highly active and persistent. Earlier this week, threat researchers observed another spam campaign in which the “Muddy Water” group has been involved.

How the infection spreads (some technical details included)

In the analyzed campaign, malicious actors are using social engineering techniques to bait potential victims from targeted organizations into enabling macros in the Microsoft office package.

It’s not the first time this attack vector is being used, but as long as it still works why not trying it, right?

In this scenario, users receive a phishing email with a document containing a VBA macro code which, if enabled, will compromise users’ systems by using a PowerShell payload.

See in the image below how the malicious document from the spam campaign looks like for the recipient.

If macros are enabled, cybercriminals will use Windows scripting host “//E” command line which is a Base64 encoded payload employing the obfuscation method.
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
360 Total Security 11.0.0.1099
 11.0.0.1099 Apr 2...harlan4096 — 09:42
NVIDIA RTX Remix gets DLSS 3.5 Ray Recon...
Ray Reconstruction...harlan4096 — 09:30
Google Chrome 124.0.6367.118/.119
Google Chrome 124....harlan4096 — 09:29
Windows Repair Toolbox 3.0.4.0
An updated version...harlan4096 — 16:25
SecureAPlus 6.8.1
SecureAPlus 6.8.1:...harlan4096 — 16:22

[-]
Birthdays
Today's Birthdays
avatar (72)divinenews
avatar (49)plajhunTat
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (36)owysykan
avatar (47)beautgok
avatar (37)axuben
avatar (43)talsmanthago
avatar (29)mocetor
avatar (44)piomaibhaict
avatar (49)kingbfef
avatar (36)izenesiq
avatar (43)centfootadoni
avatar (38)ihijudu
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
avatar (47)contjrat
avatar (39)axylisyb
avatar (42)tukrublape
avatar (39)iruqi
avatar (40)saitetib
avatar (34)ypasodiny
avatar (37)omapek
avatar (46)Geraldtuh
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (43)xclubDum
avatar (39)Stewartanilm
avatar (42)nikitaxople
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>