HomeSecurityCybercriminals abuse the MacroPack framework

Cybercriminals abuse the MacroPack framework

The MacroPack framework, a tool designed for Red Team exercises and testing, is now being used by cybercriminals to develop malicious payloads, including Havoc, Brute Ratel, and PhatomCore.

MacroPack framework cybercriminals

Cisco Talos security researchers analyzed malicious document submissions to VirusTotal from various countries, including the United States, Russia, China, and Pakistan.

These malicious documents varied from each other (in terms of lures, complexity), which probably means that many different hacking groups are abusing MacroPack in their attacks.

See also: North Korean hackers distribute FudModule rootkit via Chrome zero-day

MacroPack framework

As mentioned earlier, MacroPack is designed for use in Red Team and attack. It was created by French developer Emeric Nasi (dba BallisKit). It offers advanced features, such as anti-malware bypass, anti-reversing techniques, and the ability to create various document payloads with elements that allow it to remain undetected.

Cisco now says it has identified several sample documents that appear to be linked to MacroPack.

Victims who open these Microsoft Office will trigger a first-stage VBA code, which loads a malicious DLL that connects to the attacker's command and control (C2) server.

See also: Hackers stole $313 million worth of crypto in August

What Cisco Talos discovered

The Cisco Talos report identifies four major cybercriminal groups associated with MacroPack abuse:

China: Documents from IP addresses in China, Taiwan, and Pakistan (May-July 2024) instructed users to enable macros. The result was the installation of the Havoc and Brute Ratel payloads on victims. These payloads connect to C2 servers located in Henan, China (AS4837).

Pakistan: Documents with Pakistani military issues were uploaded from sites in Pakistan. One document, presented as a circular from the Pakistan Air Force and another presented as an employment confirmation, were deployed by Brute Ratel badgers.

Russia: A blank Excel workbook was uploaded from a Russian IP in July 2024 and delivered the PhantomCore backdoor used for espionage. The document executed multi-step VBA code that attempted to download the backdoor from a remote URL.

US: A document uploaded in March 2023 was presented as an encrypted NMLS renewal form and used Markov Chain-generated function names to evade detection. The document contained VBA code that checked for sandbox environments before attempting to download an unknown payload via mshta.exe.

Cybercriminals abuse the MacroPack framework
Cybercriminals abuse the MacroPack framework

Ransomware groups also appear to be using a cracked version of the tool to evade EDR and AV during attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Hackers Target Chinese Businesses with Cobalt Strike Payloads

The abuse of MacroPack is a worrying development for network defenders and shows that more and more cybercriminals are using legitimate tools to bypass traditional security. The use of the MacroPack framework not only offers attackers a hidden means of penetration, but also allows them to exploit the trust in these tools. As a result, organizations must remain vigilant and adapt security their, ensuring they are equipped to detect and respond to such sophisticated threats. Continuous training and awareness of these tactics is essential to developing more effective countermeasures against these evolving threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS