Since December 2021, a new trend has been observed in phishing campaigns: increased use of malicious PowerPoint files to distribute various types of malware, including RAT trojans and info-stealers (trojans that allow remote access and information theft, respectively).

According to Bleeping Computer, a report from Netskope states that cybercriminals are using PowerPoint files in conjunction with legitimate cloud services that host malware payloads.
See also: Cryptocurrency token rug pulls: Hackers hijack smart contracts
The malware deployed in the observed phishing campaign are Warzone (also known as AveMaria) and AgentTesla, two powerful RATs and info-stealers that target multiple applications. Researchers also observed the installation of malware that steals cryptocurrencies.
Hackers infect Windows devices with malware
The malicious PowerPoint attachment found in phishing emails contains an obfuscated macro that is executed through a combination of PowerShell and MSHTA, both built-in Windows tools.

The VBS script is then de-obfuscated and adds new Windows registry entries for persistence, leading to the execution of two scripts. The first retrieves AgentTesla from an external URL and the second disables Windows Defender.
Additionally, the VBS creates a scheduled task that runs a script every hour, which fetches a cryptocurrency stealer from a Blogger URL.
Malware payloads: AgentTesla, Warzone, crypto-stealer
AgentTesla is a .NET-based RAT (remote access trojan) that can steal browser passwords and clipboard contents, record keystrokes, etc.
See also: FBI: Malicious QR codes can steal your money
The second malware payload delivered in the malicious PowerPoint phishing campaign is Warzone, another RAT that Netskope did not provide many details about.
Finally, the cryptocurrency theft program checks for crypto wallets and transactions. If any are found, it replaces the recipient address with an address under the hacker's control, allowing the cryptos to be stolen.
The malware supports Bitcoin, Ethereum, XMR, DOGE and many more. More information can be found here.

PowerPoint: Used increasingly in phishing campaigns
In December 2021, Fortinet reported a similar phishing campaign, which also used PowerPoint files to distribute Agent Tesla.
This file type, like Excel, should be treated with special care, as the macro code in PP files can be dangerous and destructive.
See also: Phishing attacks: Which major companies do scammers imitate to trick victims?
In the recent phishing campaign examined by Netskope researchers, cybercriminals also leveraged cloud services, hosting malicious payloads on various legitimate platforms, making them more difficult for security solutions to detect.
Therefore, to stay safe, carefully check the emails you receive (especially if it's something you're not expecting) and keep macros disabled in the Microsoft Office suite.
Source: Bleeping Computer
