HomeSecurityPhishing: Hackers hide malware in image of James Webb

Phishing: Hackers hide malware in image of James Webb

Security researchers have discovered a new malware distribution campaign they have dubbed “GO#WEBBFUSCATOR” and it is based on phishing emails, malicious documents and… an image from the James Webb Space Telescope.

phishing malware

The malware is written in Golang, a programming language increasingly used by cybercriminals because it is cross-platform (Windows, Linux, Mac) and “resists” reverse engineering and analysis.

According to researchers at Securonix, in this new malware campaign, attackers are installing payloads, which are currently not flagged as malicious by antivirus engines, on the VirusTotal scanning platform.

See also: Crypto-mining malware masquerades as Google Translate Desktop app

How does infection occur?

The infection begins with a phishing email containing a malicious document attachment, “Geos-Rates. docx.” This document downloads a template file, which is saved to the system.

This file contains an obfuscated VBS macro that runs automatically if macros are enabled in the Office suite . The code then downloads a JPG image (“OxB36F8GEEC634.jpg”) from a remote resource (“xmlschemeformat[.]com”), decodes it into an executable file (“msdllupdate.exe”) using certutil. exe, and opens it.

James Webb malware

In an image viewer, the .JPG image shows the galaxy SMACS 0723, published by NASA in July 2022 and taken by the world's most powerful space telescope, the James Webb.

See also: FBI: Hackers exploit DeFi bugs to steal crypto

However, if opened with a text editor, the image reveals additional content disguised as a certificate, which is a Base64-encoded payload that is converted into the malicious 64-bit executable.

The payload strings are further obfuscated using ROT25, while the binary uses XOR to hide the Golang assemblies from analyzers. In addition, the Golang assemblies use case alteration to avoid signature-based detection by security.

What does the malware distributed with James Webb images do?

According to the researchers, the malicious executable achieves persistence by copying itself to '%%localappdata%%\microsoft\vault\' and adding a new registry key.

During execution, the malware establishes a DNS connection with the command and control (C2) server and sends encrypted queries.

The C2 can respond to malware by setting time intervals between connection requests, changing the nslookup timeout, or sending commands to execute via the Windows cmd.exe tool .

During testing, Securonix observed attackers executing enumeration commands on its test systems, a typical first identification step.

See also: Google launches Bug Bounty program for open source software

According to the researchers, the domains used for the campaign were registered recently (the oldest on May 29, 2022).

Securonix has provided a set of indicators of compromise (IoC). More details about this interesting phishing – malware campaign, which exploits an image of James Webb, can be found in the report .

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS