HomeSecurityPhishing scam targets OneDrive users to execute malicious PowerShell script

Phishing scam targets OneDrive users to execute malicious PowerShell script

Cybersecurity researchers are warning of a new phishing scam targeting Microsoft OneDrive users with the aim of executing a malicious PowerShell script.

onedrive phishing powershell

"The campaign relies heavily on social engineering tactics to trick users into running a PowerShell script, thereby compromising their systems," Trellix security researcher Rafael Pena said in a Monday analysis.

The cybersecurity firm is tracking a sneaky phishing and downloader campaign known as OneDrive Pastejacking. This attack is carried out via an email containing an HTML file. When the file is opened, it displays an image that mimics the OneDrive page, accompanied by an error message that reads: “Failed to connect to the cloud service 'OneDrive'. To resolve the issue, you need to manually refresh your DNS cache.”

Read also: Proofpoint: Hackers exploited bug to send phishing emails

The message includes two options: “How to fix it” and “Details.” The second option redirects the recipient to an official Microsoft Learn page for resolving DNS issues. However, if the user selects the “How to fix it” option, they will be asked to follow a series of steps. These include selecting “Windows Key + X” to open the Quick Link menu, launching PowerShell, and pasting a Base64-encoded command, supposedly to fix the problem.

“The command […] first executes ipconfig /flushdns and then creates a folder on the C: drive called “downloads,” Pena explained. It then downloads an archive file to that location, renames it, extracts its contents (i.e. “script.a3x” and “AutoIt3.exe”), and executes script.a3x using AutoIt3.exe.”

The campaign targets users from the US, South Korea, Germany, India, Ireland, Italy, Norway and the UK.

The revelation builds on similar findings from ReliaQuest, Proofpoint, and McAfee Labs, indicating that phishing attacks leveraging this technique—also known as ClickFix—are becoming increasingly widespread.

This campaign was discovered alongside another new social engineering via email, which distributes fake Windows shortcut files. These files lead to the execution of malicious payloads hosted on Discord's Content Delivery Network (CDN) infrastructure.

Phishing email campaigns have become increasingly common, such as sending Microsoft Office forms from previously compromised legitimate email accounts. Hackers try to trick their targets into revealing their Microsoft 365 login credentials by getting them to click on seemingly harmless links.

See more: New service for hackers combines phishing kits and malicious Android apps

“Hackers create legitimate-looking forms using Microsoft Office templates, embedding malicious links in them,” Perception Point said. “These forms are mass-emailed to targets and pretend to be legitimate requests (changing passwords or accessing important documents), from trusted platformssuch as Adobe and Microsoft SharePoint document viewers.”

Additionally, other waves of attacks have leveraged invoice-themed baits to trick victims into revealing their credentials on phishing pages hosted on Cloudflare R2. These credentials are then transferred to the threat actor via a Telegram.

It's no surprise that hackers are constantly looking for new methods to sneak malware through secure email gateways (SEGs) to increase the chances of their attacks succeeding.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

According to a recent report from Cofense, malicious users are exploiting SEG's scanning process for ZIP file attachments to distribute the Formbook information-stealing program via DBatLoader, also known as ModiLoader and NatsoLoader.

onedrive phishing powershell

Specifically, this involves transmitting the HTML payload as an MPEG file to avoid detection. We take advantage of the fact that many common archive and SEG exporters parse the file header information, but ignore the footer, which may contain more precise details about the file format.

Read more: CrowdStrike: Phishing attacks target German customers

“The hackers used a .ZIP file attachment and, when SEG scanned the file’s contents, it was found to contain an .MPEG video file, which was not blocked or filtered,” the company said.

When we opened this attachment with popular file extractors like 7-Zip or Power ISO, it appeared to contain an .MPEG video file, but it was unplayable. However, when the file was opened via an Outlook client or the Windows file manager, the .MPEG file was correctly identified as a .HTML [file].

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS