
A new phishing campaign is distributing LokiBot ( info - stealer malware ) and a second payload in the form of Jigsaw Ransomware .
With this malware, attackers first steal usernames and passwords stored in various applications and then install the Jigsaw Ransomware to demand ransom from victims.
Malicious Excel Spreadsheets
The exact emails sent as part of this phishing campaign have not been found, but the attachments appear to be invoices, bank transfers, orders , etc.
The phishing campaign uses attached Excel files, with names such as Swift.xlsx, orders.xlsx, Invoice For Payment.xlsx, Inquiry.xlsx.
Unlike many phishing documents, these appear legitimate or at least carefully crafted to appear trustworthy.

According to security researcher James, who discovered this phishing campaign, these attachments have used the LCG Kit, which allows them to exploit an old Microsoft Office vulnerability (CVE-2017-11882) in the Equation Editor.
If the vulnerability is successfully exploited, malware will be downloaded from a remote site and its execution will begin.

According to the researcher, cjjjjjjjjjjjjjjjjjjjj.exe is LokiBot.
The LokiBot info-stealer has the ability to steal stored credentials from various browsers, FTP, mail, and terminal programs. It then sends the data to a command and control server, which is controlled by the attacker.
Additional ransomware payload
Additionally, the LokiBot variant distributed through the phishing campaign is configured to install a variant of the Jigsaw Ransomware that encrypts a victim's files and appends the .zemblax to the file names.


The good news is that Jigsaw is easily decrypted, so if you get infected you can easily find the solution.
The bad news is that the Jigsaw Ransomware will temporarily delete your files until you pay.
Therefore, if you get infected, make sure to end the drpbx.exe process using Task Manager. Doing so will stop the Jigsaw Ransomware and prevent it from deleting your files.
As this phishing campaign uses malicious Excel spreadsheets, make sure you are using the latest security updates for your installed Officeapplications to stay protected.
