Researchers have discovered a new campaign that involves Chinese hackers running APTs and exploiting the fear and confusion caused by the coronavirus pandemic to deliver malware to Windows. This hacking attack, believed to be initiated by a long-standing group of hackers running APTs targeting various government and private entities, is exploiting the pandemic to infect targeted victims. The attackers are also using new hacking tools in this campaign to carry out an attack with suspicious RTF documents.
Evidence from this hacker attack reveals that RTF documents are equipped with Royal Road, an RTF “weapon” named by Anomali . Sometimes called the “8.t RTF exploit builder,” it is primarily used to exploit vulnerabilities in Microsoft Word ’s equation editor .
Some of the malicious documents are written in Mongolian. One of them, which refers to the Mongolian Ministry of Foreign Affairs, contains information about new cases of Coronavirus. It is worth noting that this cyberattack did not only target the Mongolian Ministry of Foreign Affairs, but also extended to other countries such as Ukraine, Russia and Belarus.
How does this attack work, though?
Once the targeted victim opens the malicious RTF document, the hackers will exploit a vulnerability in Microsoft Word for Windows and the new file named intel.wll will be injected into the Word startup folder.
After that, when Microsoft Word is launched on the infected computer, all DLL files with the WLL extension in the Word startup folder are launched as well. According to Checkpoint, like many malware, it downloads more malware – in this case, it downloads and decrypts a RAT module, also in the form of a DLL file, and loads it into memory.
The RAT module used by the hackers in this attack can take screenshots of the victim's computer screen, which it sends to the hackers. It can also list files and directories, create or delete directories, and move, delete, or download files.
