HomeSecurityGIFShell attack infects Microsoft Teams using GIFs

GIFShell attack infects Microsoft Teams using GIFs

The GIFShell attack creates a reverse shell using Microsoft Teams GIFs, allowing hackers to launch phishing attacks.

A new attack technique called “GIFShell” allows threat actors to abuse Microsoft Teams for new phishing attacks and secretly execute commands to steal data using…GIFs.

The new attack script, shared exclusively with BleepingComputer, shows how attackers can combine multiple vulnerabilities and flaws in Microsoft Teams to abuse Microsoft's legitimate infrastructure to deliver malicious files, commands, and perform data extraction via GIFs.

As data extraction takes place through Microsoft servers , the traffic will be more difficult to detect by antivirus software that sees it as legitimate Microsoft Teams traffic.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

Overall, the attack technique exploits a variety of Microsoft Teams flaws and vulnerabilities:

  • It bypasses Microsoft Teams security controls by allowing external users to send attachments to Microsoft Teams users.
  • Modifies sent attachments so that users download files from an external URL rather than the SharePoint link.
  • It spoofs Microsoft Teams attachments to appear as harmless files, but instead downloads a malicious executable file or document.
  • It exploits insecure URI schemes that allow SMB NTLM hash theft or NTLM Relay attacks.

Microsoft supports sending HTML base64 encoded GIFs, but does not scan the byte content of these GIFs. This allows malicious commands to be delivered inside a normal-looking GIF.

Microsoft stores Teams messages in an analysis-capable log file, located locally on the victim's computer and accessible by a low-privileged user .

Microsoft servers retrieve GIFs from remote servers, allowing data to be extracted via GIF filenames.

GIFShell – a reverse shell via GIF

The new attack chain was discovered by cybersecurity consultant Bobby Rauch, who found numerous vulnerabilities or flaws in Microsoft Teams that can be linked together to execute commands, extract data, bypass security controls, and carry out phishing attacks.

The main component of this attack is called “GIFShell,” which allows an attacker to create a reverse shell that delivers malicious commands via base64-encoded GIFs to Teams and outputs the output via GIFs retrieved by Microsoft’s own infrastructure.

See also: Lazarus Group targets US energy providers

To create this reverse shell, the attacker must first convince a user to install a malicious stager that executes commands and uploads the command output via a GIF URL to a Microsoft Teams web hook. However, as we know, phishing attacks work well in infecting devices, Rauch devised a new Microsoft Teams phishing attack to help with this, which we describe later.

GIFShell works by tricking a user into loading a malware executable called stager onto their device, which will continuously scan Microsoft Teams located at: $HOME\AppData\Roaming\Microsoft\Teams\IndexedDB\https_teams.microsoft.com_0.indexeddb. leveldb\*.log.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

All received messages are stored in these log files and are readable by all Windows user groups, which means that any malware on the device can access them.

Once the stager is deployed, a threat actor will create their own Microsoft Teams and communicate with other Microsoft Teams users outside their organization. Attackers can easily achieve this, as Microsoft allows external communication by default in Microsoft Teams.

To launch the attack, the threat actor can use GIFShell Python to send a message to a Microsoft Teams user containing a specially crafted GIF. This legitimate GIF image has been modified to include commands to execute on the target's machine.

When the target receives the message, the message and GIF will be saved in Microsoft Teams log files, which are monitored by the malicious stager.

See also: North Face: 200,000 accounts compromised through credential stuffing

When the stager detects a message with a GIF, it will extract the base64 encoded commands and execute them on the device. The GIFShell PoC will then take the output of the executed command and convert it to base64 text.

This base64 text is used as the filename for a remote GIF embedded in a Microsoft Teams Survey Card, which the stager submits to the Microsoft Teams public webhook.

As Microsoft Teams renders flash cards for the user, Microsoft's servers will reconnect to the attacker's server URL to retrieve the GIF, which is named using the base64 encoded output of the executed command.

The GIFShell server running on the attacker's server will receive this request and automatically decode the filename, allowing the attackers to see the output of the command being executed on the victim's device, as shown below.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

For example, a recovered GIF file named "dGhlIHVzZXIgaXM6IA0KYm9iYnlyYXVjaDYyNzRcYm9iYnlyYXVJa0K.gif" will be decoded in the output of the "whoami" command executed on the infected device:

the user is: 
bobbyrauch6274\bobbyrauIkBáë

Threat actors can continue to use the GIFShell to send more GIFs with further embedded executable commands and continue to receive the output when Microsoft attempts to retrieve the GIFs.

As these requests are made from the Microsoft website, urlp.asm.skype.com, which is used for Microsoft Teams communication, the traffic will be considered legitimate and will not be detected by security software.

This allows the GIFShell attack to exploit hidden data by mixing the output of their commands with legitimate Microsoft Teams network communication.

Even worse, since Microsoft Teams runs as a background process, the user doesn't even need to open it to receive the attacker's commands for execution.

The Microsoft Teams log file folder has also been accessed by other programs, including enterprise monitoring software, such as Veriato, and possibly malware.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

Microsoft acknowledged the research, but said it would not be fixed as no security limits were being bypassed.

"For this case, 72412, while this is great research and the team will try to improve these areas over time, these are all post-exploitation and are based on a target that has already been compromised," Microsoft told Rauch in an email shared with BleepingComputer.

"No security limits appear to be being bypassed. The team will review the issue for possible future design changes, but this will not be monitored by the security team."

Abuse of Microsoft Teams for phishing attacks

As we said before, the GIFShell requires the installation of an executable that executes commands received within GIFs.

To help with this, Rauch discovered flaws in Microsoft Teams that allowed him to send malicious files to Teams users, but forge them to appear as harmless images in phishing attacks.

"This research shows how it is possible to send very convincing phishing attachments to victims via Microsoft Teams, without any way for the user to check in advance whether the linked attachment is malicious or not," Rauch explains in his write-up on the phishing method.

As we mentioned earlier in our discussion of GIFShell, Microsoft Teams allows Microsoft Teams users to send messages to users in other tenants by default.

However, to prevent attackers from using Microsoft Teams in phishing malware attacks, Microsoft does not allow external users to send attachments to members of another tenant.

See also: Microsoft: Hotfix for blocked Windows connections

While playing around with attachments in Microsoft Teams, Rauch discovered that when someone sends a file to another user in the same tenant, Microsoft creates a SharePoint link that is embedded in a JSON POST request to the Teams endpoint

This JSON message, however, can then be modified to include any download link an attacker wants, even external links. Worse, when the JSON is sent to a user via the Teams chat endpoint, it can also be used to send attachments as an external user, bypassing Microsoft Teams security restrictions.

For example, the JSON below has been modified to display a filename of Christmas_Party_Photo.jpeg, but actually provides a remote executable file Christmas_Party_Photo.jpeg………….exe.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

When the attachment is rendered in Teams, it appears as Christmas_Party_Photo.jpeg , and when you mark it, it will continue to display that name, as shown below.

GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

However, when the user clicks the link, the attachment will download the executable file from the attacker's server.

In addition to using this Microsoft Teams spoofing phishing attack to send malicious files to external users, attackers can also modify the JSON to use Windows URIs, such as ms-excel:, to automatically launch an application to retrieve a document.

Rauch says this would allow attackers to trick users into connecting to a remote network share, allowing threat actors to steal NTLM hashes or local attackers to perform an NTLM relay to elevate privileges.

"These permitted, potentially insecure URI schemes, combined with the lack of permissions enforcement and attachment spoofing vulnerabilities, can allow a One Click RCE via NTLM relay in Microsoft Teams," Rauch explains in his report on the attack.

Rauch told BleepingComputer that he disclosed the flaws to Microsoft in May and June 2022, and despite Microsoft saying they were valid issues, they decided not to fix them immediately.

When BleepingComputer contacted Microsoft about why the bugs weren't fixed, we weren't surprised by their response regarding the GIFShell attack technique, as it requires the device to already be compromised with malware.

“This type of phishing is important to be aware of, and as always, we recommend that users practice good online habits and exercise caution when clicking on links on web pages, opening unknown files, or accepting file transfers. We evaluated the techniques reported by this researcher and determined that the two reported do not meet the threshold for a security hotfix. We are constantly looking for new ways to better resist phishing to ensure customer security, and we may take steps in a future release to help mitigate this technique.” – Microsoft spokesperson.
GIFShell attack infects Microsoft Teams using GIFs
GIFShell attack infects Microsoft Teams using GIFs

However, we were surprised that Microsoft didn't consider the ability of external attackers to bypass security checks and send attachments to another tenant as something that needed to be fixed immediately.

Additionally, it was also surprising not to immediately fix the ability to modify JSON attachment cards so that Microsoft Teams recipients could be tricked into downloading files from remote URLs.

However, Microsoft left the door open for these issues to be resolved, telling BleepingComputer that they may be addressed in future releases.

"Some lower severity vulnerabilities that do not pose an immediate risk to customers are not prioritized for an immediate security update, but will be considered for the next version or release of Windows," Microsoft explained in a statement to BleepingComputer.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS