HomeSecurityQbot malware hijacks Windows WordPad to evade detection

Qbot malware hijacks Windows WordPad to evade detection

Researchers claim that hackers have started exploiting a vulnerability in the WordPad text editor, which is preinstalled with the Windows 10 operating system, to distribute the Qbot malware.

See also: Bandit Stealer: New info-stealer malware targets browsers and crypto wallets

Qbot malware hijacks Windows WordPad to evade detection
Qbot malware hijacks Windows WordPad to evade detection

A cybersecurity researcher and member of Cryptolaemus, under the alias “ProxyLife”, discovered a new email campaign in which hackers distribute the WordPad program together with a malicious .DLL file.

When WordPad is launched, it will look for certain .DLL files it needs to run correctly. Initially, it will search for the files in the same folder where it is located - if it finds them, it will execute them automatically, even if those .DLL files are malicious.

See also: Ransomware: Ransom payments continue to be the wrong approach

DLL hijacking

This practice is commonly referred to as “DLL sideloading” or “DLL hijacking” and is a very well-known method. In the past, hackers have been observed using the Calculator application to do the same thing.

In this case, when WordPad executes the DLL, a malicious file will use an executable called Curl.exe (located in the System32 folder) to download a DLL that pretends to be a PNG. This DLL is actually Qbot, a banking trojan that can steal emails for use in further phishing and initiate the download of additional malware, such as Cobalt Strike.

By using legitimate programs, such as WordPad or Calculator, to execute malicious DLL files, hackers hope to bypass any antivirus programs and remain “silent” during the attack.

Qbot malware hijacks Windows WordPad to evade detection

See also: How does the new Hot Pixels attack steal data?

However, since this method requires the use of Curl.exe, it only works on Windows 10 and newer versions, as earlier versions did not have this program pre-installed. This doesn't offer much benefit, given that older versions are mostly reaching the end of support and users are moving towards Windows 10 and Windows 11.

Information source: techradar.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS