HomeSecurityNew phishing campaign infects victims with info-stealer and ransomware

New phishing campaign infects victims with info-stealer and ransomware

phishing campaign

A new phishing campaign is distributing LokiBot ( info - stealer malware ) and a second payload in the form of Jigsaw Ransomware .

With this malware, attackers first steal usernames and passwords stored in various applications and then install the Jigsaw Ransomware to demand ransom from victims.

Malicious Excel Spreadsheets

The exact emails sent as part of this phishing campaign have not been found, but the attachments appear to be invoices, bank transfers, orders , etc.

The phishing campaign uses attached Excel files, with names such as Swift.xlsx, orders.xlsx, Invoice For Payment.xlsx, Inquiry.xlsx.

Unlike many phishing documents, these appear legitimate or at least carefully crafted to appear trustworthy.

information stealer

According to security researcher James, who discovered this phishing campaign, these attachments have used the LCG Kit, which allows them to exploit an old Microsoft Office vulnerability (CVE-2017-11882) in the Equation Editor.

If the vulnerability is successfully exploited, malware will be downloaded from a remote site and its execution will begin.

 information stealer

According to the researcher, cjjjjjjjjjjjjjjjjjjjj.exe is LokiBot.

The LokiBot info-stealer has the ability to steal stored credentials from various browsers, FTP, mail, and terminal programs. It then sends the data to a command and control server, which is controlled by the attacker.

Additional ransomware payload

Additionally, the LokiBot variant distributed through the phishing campaign is configured to install a variant of the Jigsaw Ransomware that encrypts a victim's files and appends the .zemblax to the file names.

Ransomware phishing campaign
ransomware

The good news is that Jigsaw is easily decrypted, so if you get infected you can easily find the solution.

The bad news is that the Jigsaw Ransomware will temporarily delete your files until you pay.

Therefore, if you get infected, make sure to end the drpbx.exe process using Task Manager. Doing so will stop the Jigsaw Ransomware and prevent it from deleting your files.

As this phishing campaign uses malicious Excel spreadsheets, make sure you are using the latest security updates for your installed Officeapplications to stay protected.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS