HomeSecurityLimeRAT Trojan: Spreads using Excel file encryption technique

LimeRAT Trojan: Spreads using Excel file encryption technique

A new campaign is spreading the LimeRAT remote access Trojan using an old Excel file encryption technique. LimeRAT is a simple Trojan designed for Windows. This malware can install backdoors on infected computers and encrypt files in exactly the same way as other ransomware, add computers to botnets , and install miners . In addition, the LimeRAT Trojan can spread via attached USB, uninstall itself if a virtual machine (VM) is detected, “lock” screens, and steal data that is then sent to a command and control (C2) server using AES (Advanced Encryption Standard) encryption. In a new campaign discovered by Mimecast, the Trojan appears as a payload in Excel documents and is spread via phishing emails. The researchers said in a blog post that the Excel documents are read-only – not locked – as Excel encrypts them without requiring users to set a password.

To decrypt the file, when opened, Excel will attempt to use a built - in password, “VelvetSweatshop,” which was previously implemented by Microsoft developers . If this succeeds, Excel decrypts the file and allows macros to be launched and malicious payload to be injected, while keeping the document read-only.

LimeRAT Trojan: Spreads using Excel file encryption technique

Typically, if VelvetSweatshop decryption fails, users must enter a password. However, the read-only feature bypasses this step, reducing the number of steps required to gain access to a Windows computer. According to the researchers, the advantage of the read-only feature for Excel files is that it does not require user input, and the Microsoft Office system will not display any warning, only a notification saying that the file is read-only.

The new campaign that has been created to spread LimeRAT uses this technique, which first appeared in 2013 and was presented at a Virus Bulletin. In addition, there is a vulnerability identified as CVE-2012-0158, which hackers are exploiting. It is worth noting that this issue was reported a long time ago. However, Sophos notes that hackers are still exploiting this vulnerability in a case that is considered “notable”. Mimecast reports that hackers are also using a set of other techniques in an attempt to deceive users’ systems, encrypting the contents of the spreadsheet to hide the exploit and payload. Finally, Microsoft has been informed that this vulnerability is being used again.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS