
A phishing campaign that uses PDF documents to spread the Separ malware and steals browser and email credentials has been active for several weeks.
Since the attack began in late January, it has affected around 200 companies and over 1,000 individuals, located primarily in Southeast Asia, the Middle East, and North America – and the hackers behind the attack continue to upload stolen data daily, security researchers told Threatpost.
The effectiveness of this phishing campaign stems from a simple but dangerous tactic used by Separ to avoid detection: It uses a combination of legitimate executable files and short scripts.
“Although the attack mechanism used by this malware is very simple and no attempt has been made by the attacker to evade analysis, the increase in the number of victims infected by this malware shows that simple attacks can be much more effective,” Guy Propper said in a post on Tuesday.
Older variants of Separ have existed since November 2017, while the individuals behind it have been active since 2013, according to researchers.
What makes this attack so successful is the use of a simple but difficult technique called “living off the land.” Hackers have used this tactic in the past to launch attacks based on legitimate files that are either common within the system they are attacking or are widely used administration tools. Legitimate files can be hijacked to perform malicious operations.
For Separ, this means that it uses files and legitimate executables to carry out its malicious operations.
These legitimate executables include password and email logging tools from SecurityXploded, as well as software from NcFTP.
Attack process
The attack begins with a phishing email containing a malicious attachment – in this case a PDF document, which is supposed to be an executable file. According to the researchers, the fake documents are related to prices, shipments, and equipment specifications and appear to target businesses.
Once the victim clicks on the attached “PDF document,” the file launches wscript.exe to execute a Visual Basic Script (VB Script) called adobel.vbs.
Once the VB Script starts running, it executes a series of short batch scripts, which have various malicious functions. The scripts are disguised as fake programs associated with Adobe, the researchers said.
These scripts perform a series of malicious operations, which include changing the system's firewall settings and stealing all email and browser credentials. Meanwhile, the malware also opens an empty .jpg image to hide its activities from the victim.
To steal credentials, Separ uses password-dumping tools provided by SecurityXploded.
The malware uses a File Transfer Protocol (FTP) client program to upload its stolen data to a legitimate service called freehostia[.]com.
Ongoing attack
Access to the hosting service used by Separ in its attacks indicates that its activity is ongoing and data stolen from many other victims is being uploaded daily, the researchers said.
Researchers urge potential victims to avoid clicking on unknown or untrusted links.
