Russian hackers behind the Zebrocy malware changed their technique for delivering malware to high-profile victims and began placing the malware on Virtual Hard Drives (VHD) to avoid detection.
The technique was spotted in some recent spear-phishing campaigns by the APT28 group (Fancy Bear, Sofacy, Strontium, Sednit) which was attempting to infect systems with a variant of the Zebrocy tool.

New Zebrocy variants are not easily detected
Zebrocy is available in several programming languages (AutoIT, C++, C#, Delphi, Go, VB.NET). For its recent campaigns, the team chose the Golang-based version instead of the more common Delphi version.
Windows 10 natively supports VHD files and can mount them as external drives to allow users to view the files internally. Last year, security researchers discovered that antiviruses don't scan the contents of VHDs until the disk images are mounted.
Intezer researchers discovered a VHD uploaded to the Virus Total scanning platform from Azerbaijan in late November. Inside the image was a PDF file and an executable that appeared to be a Microsoft Word document , which was the Zebrocy malware.
The PDF is a presentation about Sinopharm International Corporation, a Chinese pharmaceutical company currently in the testing phase for a COVID-19.
The Zebrocy variant in the VHD file is new and was not easily detected by Virus Total. However, Intezer's analysis showed that the new Zebrocy is genetically similar to a Delphi variant used a year ago in a campaign against targets in Azerbaijan.
Information source: bleepingcomputer.com
