Microsoft's security team announced yesterday that it has discovered a series of malware campaigns that are distributing the Astaroth malware using "fileless" and "living-off-the-land" techniques. These techniques are favored by hackers because they are very difficult to detect by traditional antivirus programs.
The attacks were detected by the team behind Windows Defender ATP.
One of the team members said that Microsoft began to worry when it noticed a huge and sudden rise in the use of the WMIC tool (Windows Management Instrumentation Command-line).
The WMIC tool is a perfectly legitimate tool and is present in all modern versions of Windows. However, what has the company concerned is the sudden increase in its use, which is usually seen in malicious campaigns.
When Microsoft investigated further, it discovered a malicious spam campaign in which hackers were sending emailscontaining a link. The link led to a site hosting a .LNK shortcut file.
If users download and open the file, it will start running the WMIC tool and then several other legitimate Windows tools, one after the other.
The tools download additional code and execute exclusively in memory (fileless execution). No files are stored on disk, so traditional antiviruses cannot detect the malicious code, since there is nothing on disk to scan.

At the end of this process, the Astaroth trojan is downloaded and executed, which steals credentials for a wide category of applications and sends the stolen data to a remote server.
This trojan was first introduced in 2018. However, it recently appeared (in February of this year) in a campaign, targeting mainly European and Brazilian users.
The February campaign (analyzed by Cybereason) is similar to the one discovered by Microsoft.
And this also targets users in Brazil. A Microsoft spokesperson said that more than 95% of the «infections» from Astaroth originate from Brazil.
Also, both campaigns used almost the same tools and attack methods. The hackers used fileless and “living-off-the-land” techniques.
In the “living-off-the-land” technique, hackers use legitimate tools that already exist on the target system. This makes it difficult to detect, as it is perceived as a legitimate tool.
This technique has become extremely popular in recent years and has been further developed.
This means that protection programs must evolve further so that they can also detect threatsthat come from fileless and "living-off-the-land" techniques.
