HomeSecurityNew "military-themed" phishing campaign targets Pakistan

New “military-themed” phishing campaign targets Pakistan

Cybersecurity researchers have shed light on a new phishing campaign targeting Pakistan using a backdoor and phishing military-themed documents to carry out attacks.

phishing

"While there are many ways to deploy malware today, threat actors have used ZIP files with encrypted content that are password-protected," researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said in a report shared with The Hacker News.

Read more: Malicious advertising campaign spreads Oyster Backdoor

The campaign is notable for its lack of sophistication and use of simple payloads to achieve remote access to target computers.

The emails contain a ZIP file whose contents include information about the meeting with the International Military-Technical Forum Army 2024, an event actually organized by the Ministry of Defense of the Russian Federation. The event is scheduled to take place in Moscow in mid-August 2024.

See also: Quishing: Phishing emails with QR codes target Chinese people

Inside the ZIP is a Microsoft Compiled HTML Help (CHM) file and a hidden executable file ("RuntimeIndexer.exe"), which, when opened, displays the meeting details as well as some images, but secretly runs the executable file as soon as the user clicks anywhere in the document.

The executable file is designed to function as a backdoor that establishes connections to a remote server via TCP to receive commands that are then executed on the compromised computer.

Read also: Chinese hackers UNC3886 exploit Fortinet, Ivanti and VMware vulnerabilities

In addition to transferring system information, it executes commands via cmd.exe, collects the results of the action, and outputs them back to the server. This includes executing commands such as systeminfo, tasklist, curl to extract the public IP address using ip-api[.]com, and schtasks to maintain its activity.

phishing

"This backdoor essentially functions as a command-line-based remote access trojan (RAT) that provides the hacker continuous and secure access to the infected system," according to the researchers.

See more: ValleyRAT malware resurfaces with new data-stealing tactics

Source: thehackernews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS