Malicious actors, likely based in Russia, are using a new code execution technique based on mouse movement, triggering a malicious PowerShell in Microsoft PowerPoint presentations.
See also: How to use a live camera feed in Microsoft Powerpoint

No malicious macro is required to execute and download the payload from the malicious code, for a more insidious attack.
A report from cyber threat intelligence firm Cluster25 says that APT28 (also known as “ Fancy Bear ”), a threat group linked to the Main Intelligence Directorate of the Russian General Staff, used the new technique to deliver the Graphite malware on September 9.
The threat actor lures targets with a PowerPoint (.PPT) file that is allegedly associated with the Organization for Economic Co-operation and Development (OECD), an intergovernmental organization that works to stimulate economic progress and trade worldwide.
Within the PPT file are two slides, both with instructions in English and French for using the Interpretation option in the Zoom video conferencing application .
The PPT file contains a hyperlink that acts as a trigger to launch a malicious PowerShell script using the SyncAppvPublishingServer utility . This technique has been documented since June 2017. Several researchers explained at the time how the infection works without a malicious macro being embedded inside an Office document .
Based on the metadata found, Cluster25 says the hackers were preparing the campaign between January and February, although the URLs used in the attacks appeared active in August and September.
See also: PowerPoint files are used to distribute RATs and info-stealers
Researchers actor is targeting entities in the defense and government sectors of European Union and Eastern European countries and believe the espionage campaign is ongoing.

When the decoy document is opened in presentation mode and the victim hovers over a hyperlink, a malicious PowerShell script is triggered to download a JPEG file (“DSC0002.jpeg”) from a Microsoft OneDrive.
JPEG is an encrypted DLL file (lmapi2.dll), which is decrypted and dropped into the 'C:\ProgramData\' directory, later executed via rundll32.exe. A persistence registry key is also created for the DLL.
Subsequently, the lmapi2.dll retrieves and decrypts a second JPEG file and loads it into memory, in a new thread that had been previously created by the DLL.
Cluster25 clarifies that each of the strings in the recently retrieved file requires a different XOR key for deobfuscation. The resulting payload is the Graphite malicious software in a portable executable format (PE).
See also: How to change the background in Microsoft PowerPoint
Graphite abuses the Microsoft Graph API and OneDrive to communicate with the command and control server (C2). The threat actor has access to the service using a static client identifier to obtain a valid OAuth2 token.
With the new OAuth2 token, Graphite queries the Microsoft Graph API for new commands by enumerating the child files in the OneDrive control subdirectory, researchers explain.
The purpose of the malicious software Graphite is to allow the intruder to load other malicious software into the system memory.
