Cybersecurity researchers have shed light on a new phishing campaign targeting Pakistan using a backdoor and phishing military-themed documents to carry out attacks.

"While there are many ways to deploy malware today, threat actors have used ZIP files with encrypted content that are password-protected," researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said in a report shared with The Hacker News.
Read more: Malicious advertising campaign spreads Oyster Backdoor
The campaign is notable for its lack of sophistication and use of simple payloads to achieve remote access to target computers.
The emails contain a ZIP file whose contents include information about the meeting with the International Military-Technical Forum Army 2024, an event actually organized by the Ministry of Defense of the Russian Federation. The event is scheduled to take place in Moscow in mid-August 2024.
See also: Quishing: Phishing emails with QR codes target Chinese people
Inside the ZIP is a Microsoft Compiled HTML Help (CHM) file and a hidden executable file ("RuntimeIndexer.exe"), which, when opened, displays the meeting details as well as some images, but secretly runs the executable file as soon as the user clicks anywhere in the document.
The executable file is designed to function as a backdoor that establishes connections to a remote server via TCP to receive commands that are then executed on the compromised computer.
Read also: Chinese hackers UNC3886 exploit Fortinet, Ivanti and VMware vulnerabilities
In addition to transferring system information, it executes commands via cmd.exe, collects the results of the action, and outputs them back to the server. This includes executing commands such as systeminfo, tasklist, curl to extract the public IP address using ip-api[.]com, and schtasks to maintain its activity.

"This backdoor essentially functions as a command-line-based remote access trojan (RAT) that provides the hacker continuous and secure access to the infected system," according to the researchers.
See more: ValleyRAT malware resurfaces with new data-stealing tactics
Source: thehackernews
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
