HomeSecurityMicrosoft Exchange targeted for IcedID attacks

Microsoft Exchange targeted for IcedID attacks

IcedID malware distribution has increased! The reason? A new campaign is hacking existing email conversation threads and injecting malicious payloads that are difficult to detect.

IcedID is a banking trojan first detected in 2017, primarily used to deploy second-stage malware, such as other loaders or ransomware.

Microsoft Exchange targeted for IcedID attacks

Its operators are believed to be initial access brokers who compromise networks and then sell the access to other cybercriminals.

The ongoing IcedID campaign was discovered this month by researchers at Intezer, who shared their findings with Bleeping Computer ahead of publication.

See also: CISA adds 66 vulnerabilities to the "Known Exploited Vulnerabilities" list

How the attack works

The main method of conversation hijacking is to take control of a primary email account that is participating in a conversation with the target and then send a phishing message designed to appear as a continuation of the thread.

Therefore, when the target receives a reply message with an attachment named and presented as something related to the previous conversation, the chances of suspecting fraud are reduced to a minimum.

Intezer explains that there are indications that threat actors are targeting vulnerable Microsoft Exchange servers to steal credentials, as many of the compromised endpoints they found are public and unpatched.

Additionally, in this campaign, analysts have seen malicious phishing messages sent from internal Exchange servers, using local IP addresses in a more trusted domain and, therefore, unlikely to be flagged as suspicious.

Microsoft Exchange targeted for IcedID attacks

The email attachment sent to targets is a ZIP file containing an ISO file, which in turn encloses an LNK file and a DLL file. If the victim double-clicks on “document.lnk,” the DLL launches to set up the IcedID loader.

See also: Google fixes Chrome zero-day bug used in attacks

The IcedID GZiploader is stored in encrypted form in the resource section of the binary file and after decoding, it is placed in memory and executed.

The host is then fingerprinted and basic system information is sent to the C2 via an HTTP GET request.

Finally, the C2 responds by sending a payload to the infected machine, although this step was not performed during Intezer's analysis.

IcedID

See also: FCC: Kaspersky poses a risk to US national security

Microsoft released fixes for the ProxyLogon and ProxyShell vulnerabilities a year ago, so if you haven't implemented the company's security solutions, you're really late and at risk.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS