HomeSecurityMalicious Excel XLL add-ins promote RedLine malware

Malicious Excel XLL add-ins promote RedLine malware

Cybercriminals are spamming website contact forms and discussion forums to distribute Excel XLL files that download and install the RedLine, which steals information and passwords.

Excel XLL

See also: Microsoft Excel: How to change the date format

This is a Trojanthat steals information and cookies, usernames and passwords, as well as credit cards stored in web browsers, as well as FTP credentials and files from an infected device.

In addition to stealing data, RedLine can execute commands, download and execute further malware, and create screenshots of the active Windows screen.

All this data is collected and sent to attackers to be sold on illegal markets or used for other malicious and fraudulent activities.

Contact forms can take many different forms, including fake advertising requests, free vacation guides, and website promotions.

However, as revealed, this is a widespread campaign targeting many websites that use public forums or article comment systems.

In some cases, malicious actors have created fake websites to host the malicious Excel XLL files used to install the malware.

For example, one campaign used a spam message and a fake website that mimicked the legitimate website Plutio.

Other spam messages pretend to be payment reports, advertising requests, or gift guides with links to malicious XLL files hosted on Google Drive.

See also: Google Drive update: New features in the Android version

Of particular interest is a lure targeting website owners with requests to advertise on their site, asking them to review the terms of the offer. This leads to a malicious “terms.xll” file that installs the malware.

These spam campaigns are designed to promote malicious Excel XLL files that download and install the RedLine malware on victims' Windows devices.

RedLine

An XLL file is an add-in that allows developers to extend Excel's functionality by reading and writing data, importing data from other sources, or creating custom functions to perform various tasks.

The XLL file is simply a DLL file, which includes an "xlAutoOpen" function that is executed by Microsoft Excel when the add-in is opened.

Manually running the DLL with the regsvr32.exe command or the “ rundll32 name.xll, xlAutoOpen ” command will extract the wget.exe program to the %UserProfile% folder and use it to download the RedLine binary from a remote location.

This malicious binary is saved as %UserProfile%\JavaBridge32.exe and then executed.

A registry autorun entry will also be created to automatically launch the RedLine information theft program every time victims log on to Windows.

Once the malware is executed, it will search for valuable data to steal, including credentials and credit cards stored in Chrome, Edge, Firefox, Brave, and Opera browsers.

See also: Opera's new update promises privacy protection!

If you have fallen victim to this campaign, you should assume that your saved passwords have been compromised and change them immediately. Additionally, if you have credit cards saved in your browsers, you should contact your credit card company to notify them of the incident.

Since XLL files are executable, threat actors can use them to perform a variety of malicious activities on a device. Therefore, you should never open one unless it comes from a trusted source.

These files are generally not sent as attachments, but are installed through another program or through the Windows administrator.

So, if you receive an email or other message distributing these types of files, simply delete the message and report it as spam.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS