Security researchers have discovered a new malware distribution campaign they have dubbed “GO#WEBBFUSCATOR” and it is based on phishing emails, malicious documents and… an image from the James Webb Space Telescope.

The malware is written in Golang, a programming language increasingly used by cybercriminals because it is cross-platform (Windows, Linux, Mac) and “resists” reverse engineering and analysis.
According to researchers at Securonix, in this new malware campaign, attackers are installing payloads, which are currently not flagged as malicious by antivirus engines, on the VirusTotal scanning platform.
See also: Crypto-mining malware masquerades as Google Translate Desktop app
How does infection occur?
The infection begins with a phishing email containing a malicious document attachment, “Geos-Rates. docx.” This document downloads a template file, which is saved to the system.
This file contains an obfuscated VBS macro that runs automatically if macros are enabled in the Office suite . The code then downloads a JPG image (“OxB36F8GEEC634.jpg”) from a remote resource (“xmlschemeformat[.]com”), decodes it into an executable file (“msdllupdate.exe”) using certutil. exe, and opens it.

In an image viewer, the .JPG image shows the galaxy SMACS 0723, published by NASA in July 2022 and taken by the world's most powerful space telescope, the James Webb.
See also: FBI: Hackers exploit DeFi bugs to steal crypto
However, if opened with a text editor, the image reveals additional content disguised as a certificate, which is a Base64-encoded payload that is converted into the malicious 64-bit executable.
The payload strings are further obfuscated using ROT25, while the binary uses XOR to hide the Golang assemblies from analyzers. In addition, the Golang assemblies use case alteration to avoid signature-based detection by security.
What does the malware distributed with James Webb images do?
According to the researchers, the malicious executable achieves persistence by copying itself to '%%localappdata%%\microsoft\vault\' and adding a new registry key.
During execution, the malware establishes a DNS connection with the command and control (C2) server and sends encrypted queries.
The C2 can respond to malware by setting time intervals between connection requests, changing the nslookup timeout, or sending commands to execute via the Windows cmd.exe tool .
During testing, Securonix observed attackers executing enumeration commands on its test systems, a typical first identification step.
See also: Google launches Bug Bounty program for open source software
According to the researchers, the domains used for the campaign were registered recently (the oldest on May 29, 2022).
Securonix has provided a set of indicators of compromise (IoC). More details about this interesting phishing – malware campaign, which exploits an image of James Webb, can be found in the report .
Source: www.bleepingcomputer.com
