HomeSecurityMalware most commonly distributed through malicious attachments

Malware most commonly distributed via malicious attachments

One of the most well-known ways to distribute malware is through malicious email attachments. Attackers send phishing emails that contain supposedly invoices, invitations, information , eFaxes, voicemails, and more. These are usually documents Word and Excelthat, when opened, trigger macros that install malware.

malware

However, to enable macros, the user must click “Enable Editing” or “Enable Content.” This should never be done.

Malware distributors trick users into clicking these buttons, creating Word and Excel documents that contain text and images, but then stating that there is a problem with the document's display. Users will need to enable the content to view the document properly.

The combination of text and images in these malicious attachments is called “document templates.”

But which malware is most commonly distributed through malicious attachments?

BazarLoader

BazarLoader is a malware targeting corporate networks and was developed by the team behind the TrickBot trojan . Its installation allows remote access to the victim's computer , which is then used to compromise the rest of the network .

After installing BazarLoader, attackers deploy Ryuk ransomware to encrypt all devices on a network.

The malware is usually distributed via phishing emails that contain links to supposedly documents . The documents appear with some problem so that you can download them. In reality, they are an executable that installs BazarLoader.

attachments

Dridex

This is an advanced banking Trojan that was first detected in 2014 and is constantly evolving. The malware is used to steal passwords, provide remote access to a computer , and perform other malicious activities.

Typically, Dridex is used for the first stage of a ransomware attack (BitPaymer or Dridex). Another ransomware, known as WastedLocker, is also believed to be linked to Dridex, but not all experts agree with this.

The Dridex gang tends to use more standardized document templates that display small or unclear content and ask victims to click “Enable Content” to see it better.

It also uses documents that appear to be information about DHL and UPS. Again, users are asked to click “Enable Content” to view the information.

The Dridex gang uses images with company logos to trick users into enabling macros.

attachments

Emotet

Emotet is the malware that is most commonly distributed via malicious attachments. Emotet steals the email and uses the infected computer to send more spam emails to other victims.

Users infected with Emotet are further infected with trojans such as TrickBot and QakBot. Both Trojans are used to steal passwords ,cookies, files, and compromise the entire network.

Ultimately, if a network is infected by TrickBot, it will likely also be affected by Ryuk or Conti ransomware. Those affected by QakBot may also be affected by ProLock ransomware.

And in this case, users are asked to enable macros to better view the content.

malware

QakBot

QakBot , or QBot , is a banking trojan that also spreads through phishing campaigns, specifically via malicious Word attachments. QakBot steals banking information, installs other malware, and allows remote access to a network .

QakBot, like some of the malware above, is also associated with ransomware, such as ProLock.

Executables

Finally, users should keep in mind that they should never open attachments with extensions: .vbs, .js, .exe, .ps1, .jar, .bat, .com or .scr as they can be used to execute commands on a computer.

Since most email services, such as Office and Gmail, block “executable” attachments, malware distributors send them in password-protected files (which are provided in the email). This way, the malicious attachments bypass the security and reach the recipient.

Unfortunately, Microsoft has decided to hide file extensions, which makes it easier for criminals. Because of this, BleepingComputer strongly recommends that all Windows users allow file extensions to be displayed to avoid anything dangerous.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS