HomeSecurityHackers infect systems using Metasploit and malicious Word documents

Hackers infect systems using Metasploit and malicious Word documents

Researchers have recently discovered a new hacking group, dubbed TA2101 , that is attacking German and Italian companies with the aim of installing backdoor malware on networks their . The TA2101 hackers use legitimate penetration testing tools and backdoor frameworks , such as Cobalt Strike and Metasploit, to exploit victims’ systems.hackers

Typically, these tools are used by companies to identify vulnerabilities and protect their systems, but we have also seen other hacking groups, such as Cobalt Group, APT32, and APT19, use them to develop malware.

Attackers typically start their attacks with phishing techniques and social engineering and continue with banking Trojans and ransomware.

Researchers also discovered that the new hacking group TA2101 used the Maze ransomware to attack an Italian company, as well as the social engineering technique.

Windows Exploitation via Malicious Word Documents

The attacks by the TA2101 group were discovered by researchers at Proofpoint. The malicious campaign took place between October 16 and November 12, 2019. The hackers sent malicious emails to companies in Germany, Italy, and the United States. Their main targets were IT services, construction companies, and healthcare organizations.

According to the researchers, most of the emails contained malicious Word documents.

The message urged victims to open the malicious attachment. If users clicked on the document, it triggered the execution of a PowerShell script.

The Powershell script, in turn, downloaded and installed the Maze ransomware on the victim's device.

The hackers sent different emails to the victims. In some of them, the sender appeared to be the German Federal Ministry of Finance. Victims were supposed to open the malicious document to find information on how to avoid further taxation and penalties.

Recently, Proofpoint researchers detected another campaign of emails containing malicious Word documents, which infected victims' systems with the IcedID banking Trojan.

Hackers infect systems using Metasploit and malicious Word documents

In that campaign, too, the malicious document led to the installation of malware, the IcedID payload, on companies’ systems. The primary target of the campaign was healthcare organizations. The process of infecting the systems was the same as the recent TA2101 campaign.

The techniques used by this particular hacking group are very sophisticated and show that the hackers are very experienced and ready for many more attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS