HomeSecurityPowerPoint files are used to distribute RATs and info-stealers

PowerPoint files are used to distribute RATs and info-stealers

Since December 2021, a new trend has been observed in phishing campaigns: increased use of malicious PowerPoint files to distribute various types of malware, including RAT trojans and info-stealers (trojans that allow remote access and information theft, respectively).

PowerPoint phishing

According to Bleeping Computer, a report from Netskope states that cybercriminals are using PowerPoint files in conjunction with legitimate cloud services that host malware payloads.

See also: Cryptocurrency token rug pulls: Hackers hijack smart contracts

The malware deployed in the observed phishing campaign are Warzone (also known as AveMaria) and AgentTesla, two powerful RATs and info-stealers that target multiple applications. Researchers also observed the installation of malware that steals cryptocurrencies.

Hackers infect Windows devices with malware

The malicious PowerPoint attachment found in phishing emails contains an obfuscated macro that is executed through a combination of PowerShell and MSHTA, both built-in Windows tools.

PowerPoint files are used to distribute RATs and info-stealers

The VBS script is then de-obfuscated and adds new Windows registry entries for persistence, leading to the execution of two scripts. The first retrieves AgentTesla from an external URL and the second disables Windows Defender.

Additionally, the VBS creates a scheduled task that runs a script every hour, which fetches a cryptocurrency stealer from a Blogger URL.

Malware payloads: AgentTesla, Warzone, crypto-stealer

AgentTesla is a .NET-based RAT (remote access trojan) that can steal browser passwords and clipboard contents, record keystrokes, etc.

See also: FBI: Malicious QR codes can steal your money

The second malware payload delivered in the malicious PowerPoint phishing campaign is Warzone, another RAT that Netskope did not provide many details about.

Finally, the cryptocurrency theft program checks for crypto wallets and transactions. If any are found, it replaces the recipient address with an address under the hacker's control, allowing the cryptos to be stolen.

The malware supports Bitcoin, Ethereum, XMR, DOGE and many more. More information can be found here.

PowerPoint RAT malware

PowerPoint: Used increasingly in phishing campaigns

In December 2021, Fortinet reported a similar phishing campaign, which also used PowerPoint files to distribute Agent Tesla.

This file type, like Excel, should be treated with special care, as the macro code in PP files can be dangerous and destructive.

See also: Phishing attacks: Which major companies do scammers imitate to trick victims?

In the recent phishing campaign examined by Netskope researchers, cybercriminals also leveraged cloud services, hosting malicious payloads on various legitimate platforms, making them more difficult for security solutions to detect.

Therefore, to stay safe, carefully check the emails you receive (especially if it's something you're not expecting) and keep macros disabled in the Microsoft Office suite.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS