FreakyShelly: experts Kaspersky Lab have discovered a feature in popular document creation software that has been used by attackers to launch successful targeted attacks. Using a malicious application that is activated when a simple office, information about the software installed on the victim’s device is automatically sent to the attackers without any user interaction required.
This data allows attackers to understand the type of exploit they should use to compromise the targeted device. 
It doesn’t matter what kind of device the document is opened on: the attack technique works on both desktop and mobile versions of the popular word processing software. Kaspersky Lab has observed this method of profiling potential victims being used in the wild by at least one cyber espionage actor, which the company’s researchers are calling FreakyShelly. Kaspersky Lab has reported the issue to the software vendor, but it has not yet been fully patched.
Not long ago, while investigating targeted FreakyShelly attacks, Kaspersky Lab experts detected spear-phishing emails being sent in OLE2 documents (these use Object Linking and Embedding technology that helps applications create complex documents containing information from various sources, including the Internet).
A quick preview of the file didn't arouse any suspicion or mistrust. It included a set of useful tips on how to best use the Google search engine and didn't contain any known exploits or malicious macros. However, a closer look at the document's structure showed that, when opened, the document for some reason sent a specific GET request to an external website.
The GET request contained information about the browser used on the device, the operating system version, as well as data about some other software installed on the attacked device. The problem was that the application had no need to send any kind of request to this website.
Further research by Kaspersky Lab showed that the attack works because of the way technical information about document elements is processed and stored. Each digital document contains specific meta data about the format, text location and source, where images for the document should be taken from (if any), and other parameters. Once opened, the office application will read these parameters and then create the document using them as a “map”.
Based on the results of Kaspersky Lab's research, the parameter responsible for marking the location of images used in the document can be changed by attackers through sophisticated code manipulation and force the document to point to the website owned by the threat actor.
“Although this feature does not aid the malware attack, it is dangerous because it can effectively support malicious activity with almost zero user interaction and is able to reach many people around the world, as the affected software is very popular. So far, we have seen this feature used in only one case. However, since it is really difficult to detect, we expect that more actors may start using the technique in the future,” said Alexander Liskin, Heuristic Detection Group Manager at Kaspersky Lab.
In order to avoid falling victim to such an attack, Kaspersky Lab experts advise users to implement the following practices:
- Avoid opening emails sent from unknown addresses, as well as opening any attachments in such emails.
- Use proven security solutions that are capable of detecting such attacks.
You can find the full research in a dedicated blogpost on the Securelist.com website, which also includes further technical information about the operation.
