Palo Alto Networks' Unit 42 researchers have discovered a new phishing campaign that involves sending emails containing ,password-protected documents as well as a legitimate tool remote access . The goal is to gain access to networks victims'
The phishing campaign began in January and uses several techniques to compromise victims' systems and gain remote access to networks.
Victims receive phishing emails that include a password-protected document. The message states that the password has been set to protect the confidential data contained in the document. Most of the emails are related to refunds, online transactions, and invoices.
The password is included in the phishing email.
Unlocking the document allows macros to be activated and executes the commands necessary for the next stages of the attack. Hackers use PowerShell to install a remote access tool and other mechanisms that will allow them to stay inside the system.
The tool being installed is NetSupport Manager, a legitimate software often used in IT support.
However, if used by malicious hackers it can allow information to be stolen or it can help carry out a more dangerous and long-term plan. For example, it could be used by attackers to monitor the victim's incoming and outgoing emails. In this way, the attackers get information about other users. They can then carry out other phishing attacks targeting other people.
The bad thing is that antivirus software cannot detect NetSupport Manager as malicious, because it is a legitimate product.
Researchers yet discovered the ultimate purpose of this phishing campaign. However, since macros are required to be enabled, IT administrators can protect users by disabling macros by default. Additionally, users should be very careful with emails they receive, especially if they come from unknown sources.

