A new technique for infecting users with malware has been discovered by security engineers. While this attack relies on users having Word documents open, it does not require the use and execution of macros to get the malware onto their computer.
Researchers at Trustwave Spiderlabs say that crooks are using this multi-phase, macro-free technique to infect users with a password-stealing program. Currently, evidence suggests that only one group is using this method, but it won't be long before others adopt it.
The malware's operating mode is described below and is based on a large number of resources (DOCX, RTF, HTA, VBScript and PowerShell).
- The victim receives a spam email with a DOCX file attached.
- The user downloads and opens the DOCX file.
- The DOCX file contains OLE (Object Linking And Embedding) technology.
- OLE downloads and opens an RTF file (disguised as a DOC).
- The DOC file uses the CVE-2017-11882 vulnerability.
- The malicious code executes an MSHTA command line.
- The MSHTA command line downloads and executes an HTA file.
- The HTA file contains a VBScript that decompresses a PowerShell script.
- PowerShell downloads and installs the password-sniffing software.
- The malware steals passwords from browsers, email, and FTP clients.
- The malware uploads the data to a remote server.
The only way to stay safe is to somehow stop one of the above phases of the malware. In any case, the easiest way is to update Windows and Office (Word, Excel, etc.).
The January 2018 security patch fixes this vulnerability and is recommended for all users to install.
