State-backed hacking groups are exploiting a simple but effective technique to enhance phishing campaigns to spread malware and steal information of interest to the governments that fund them.

See also: Discord malware campaign targets crypto and NFT communities
Cybersecurity researchers at Proofpoint say that advanced persistent threat (APT) groups working on behalf of Russian, Chinese, and Indian interests are using rich text format (RTF) template injections.
While the use of RTF text file attachments in phishing emails is not new, the technique used by hackers is easier and more effective because it is harder to detect by antivirus software – and many organizations do not block RTF files by default because they are part of everyday business operations.
The technique is RTF template injection. By changing the document formatting properties of an RTF file, it is possible for attackers to “weaponize” an RTF file to retrieve remote content from a URL controlled by the attackers, enabling them to secretly retrieve a malware payload that is installed on the victim’s computer.
Attackers can use RTF template injections to open documents in Microsoft Word, which will use the malicious URL to retrieve the payload, while also using Word to display the decoy document.
This approach may require tricking users into allowing editing or allowing the content to begin the process of downloading the payload, but with the right form of social engineering, the victim can be tricked into allowing all of the above.
It is not a complex technique, but because it is simple and reliable to use, it has become popular in many nation-state hacking operations, which can deploy RTF attacks instead of other, more complex attacks, since they still have the same results.
See also: New JavaScript malware infects Windows PCs with RATs

Despite the “Advanced” designation, if APT actors do their job well, they will expend the least resources and complexity required to gain access to organizations, said Sherrod DeGrippo, vice president of threat research and detection at Proofpoint.
According to researchers, the oldest known case of an APT group using earliest in a campaign was in February 2021. These injections were carried out by DoNot Team, an APT group that has been linked to Indian state interests.
Since then, other APT groups have also deployed RTF injections as part of their campaigns. For example, TA423, also known as Leviathan, a China-linked APT group, has used RTF attacks in multiple campaigns since April.
See also: Hackers deploy Linux malware on e-commerce servers
In October, researchers identified Gamaredon – an offensive hacking group linked to the Russian Federal Security Service (FSB) that uses RTF template injection documents in attacks, impersonating the Ukrainian Ministry of Defense.
While only a few APT groups have attempted to develop RTF-based attacks so far, researchers warn that the technique's effectiveness combined with its ease of use is likely to lead to its further adoption.
Information source: zdnet.com
