HomeSecuritySerpent malware abuses Chocolatey Windows

Serpent malware abuses Chocolatey Windows

A new phishing campaign is abusing the popular Chocolatey Windows package manager to install a new backdoor malware called "Serpent" on systems of French government agencies and large construction companies.

See also: Windows zero-day flaw remains unpatched

Snake

Chocolatey is an open source package manager for Windows, allowing users to install and manage over 9,000 applications and any dependencies via the command line.

In a new phishing campaign called Serpent discovered by Proofpoint, threat actors use a complex infection chain consisting of Microsoft Word documents with macros, the Chocolatey package manager, and images to infect devices while bypassing detection.

The new phishing campaign targets French organizations in the construction, real estate, and state-owned industries.

The Serpent attack begins with an email impersonating the General Data Protection Regulation (GDPR) agency . This email includes an attached Word document containing malicious code.

See also: BitRAT malware: Appears as Windows 10 license activator and infects users

If opened and content is enabled, Serpent's malicious macro retrieves an image of Swiper the Fox from the Dora the Explorer cartoon series.

However, this image is not completely harmless, as it uses Stenography to hide a PowerShell that the macros will execute. Stenography is used to hide data to avoid detection by users and antivirus tools, as it looks like a normal image.

Serpent malware abuses Chocolatey Windows

The Serpent PowerShell script will first download and install the Chocolatey Windows package manager, which is then used to install the Python and the PIP package installer.

Chocolatey is also used to avoid detection by security software, as it is commonly used in corporate environments for remote software management and may be whitelisted in IT environments.

Finally, a second steganographic image is downloaded to load the Serpent backdoor, which is Python-based malware, hence the need for the previously installed packages in the previous steps.

See also: Western Digital: Critical bug in EdgeRover desktop app affects Windows/macOS

Once loaded, the Serpent malware will contact the attacker's command and control server to receive commands to execute on the infected device.

Proofpoint says the backdoor can execute any command sent by the attacks, allowing threat actors to download further malware, open reverse shells, and gain full access to the device.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS