HomeSecurityXWorm malware exploits Follina vulnerability in new attacks

XWorm malware exploits Follina vulnerability in new attacks

The malicious software XWorm exploits the Follina vulnerability in a new wave of attacks

Cybersecurity researchers discovered an ongoing phishing campaign that uses a unique attack chain to deliver the XWorm malware to targeted systems.

XWorm Follina
XWorm malware exploits Follina vulnerability in new attacks

Securonix, which monitors the cluster of activities called MEME#4CHAN, said some of the attacks primarily targeted manufacturing companies and healthcare clinics located in Germany.

«The attack campaign apparently leveraged unusual PowerShell code full of memes, followed by a heavy payload XWorm to infect its victims», said security researchers Den Iuzvyk, Tim Peck and Oleg Kolesnikov in a new analysis shared on The Hacker News.

The report builds on recent findings from Elastic Security Labs, which revealed that the threat actor was using reservation-themed bait to trick victims into opening malicious documents capable of delivering the XWorm and Agent Tesla payloads.

The attack starts with phishing attacks that distribute Microsoft Word documents, which instead of using macros use the Follina vulnerability (CVE-2022-30190, CVSS score: 7.8) to drop an obfuscated PowerShell script.

From there, threat actors abuse a PowerShell script to bypass the Antimalware Scan Interface (AMSI), disable Microsoft Defender, create persistence, and ultimately launch the .NET binary containing XWorm.

XWorm malware exploits Follina vulnerability in new attacks

It is interesting that one of the variables in the PowerShell script is called “$CHOTAbheem”, which is probably a reference to Chhota Bheem, an Indian comedic adventure television cartoon series.

“Based on a quick check, it appears that the individual or group responsible for the attack could have a Middle Eastern/Indian background, although the final attribution has not yet been confirmed”, the researchers said at The Hacker News, noting that such keywords could also be used as cover.

XWorm is a commodity malware advertised for sale on underground forums and has a wide range of functions that allow it to collect sensitive information from infected hosts.

The malware is a Swiss army knife, as it can perform Clipper, DDoS , and ransomware, spread via USB, and drop additional malware.

The exact origin of the threat factor is not currently clear, however, Securonix stated that the attack methodology shares artifacts similar to those of TA558, which has been observed to affect the hospitality sector in the past.

"Although phishing emails rarely use Microsoft Office since Microsoft made the decision to disable macros by default, today we see evidence that it is still important to be cautious about malicious document files, especially in this case where there was no VBscript execution from macros," the researchers said.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS