HomeSecurityMalicious code in images distributes VIP Keylogger & 0bj3ctivity malware

Malicious code in images distributes VIP Keylogger & 0bj3ctivity malware

HP Wolf Security has identified two campaigns where hackers hide malicious code in images and infect victims with the VIP Keylogger and 0bj3ctivity Stealer malware.

malicious code image

“ In both campaigns, the attackers hid malicious code in images they uploaded to archive[.]org, a website that hosts archives. They used the same .NET loader to install the final payloads ,” HP Wolf Security said in its Threat Insights Report for Q3 2024.

VIP Keylogger

The attacks begin with a phishing email with the subject line "Invoices and Purchase Orders." Recipients are asked to open malicious attachments, such as Microsoft Excel documents. When these documents are opened, a vulnerability in the Equation Editor (CVE-2017-11882) is exploited to download a VBScript file.

The script is designed to decode and execute a PowerShell script that retrieves an image hosted on archive[.]org and extracts a Base64-encoded code. This is then decoded into a .NET executable and executed.

See also: MikroTik botnet uses SPF DNS records to spread malware

The .NET executable serves as a loader to download the VIP Keylogger malware from a URL. It also allows its execution, which leads to the theft of various data from infected systems (keystrokes, clipboard contents, screenshots, and credentials).

0bj3ctivity Stealer malware

The second campaign, which is similar, also starts with phishing emails containing malicious archive files. These messages, which are presented as requests for offers, try to trick visitors into opening a JavaScript file within the archive . A PowerShell script is then executed .

The PowerShell script downloads an image from a remote server, parses the code, and executes the .NET loader (also used in the VIP Keylogger campaign). However, this attack chain ends up delivering the 0bj3ctivity Stealer malware.

HP Wolf Security has observed that hackers are also resorting to HTML smuggling to install the XWorm remote access trojan (RAT), via an AutoIt dropper.

See also: USA: FBI removes PlugX malware from thousands of computers

“In particular, the HTML files carried characteristics that suggest they were written with the help of GenAI,” HP said. “The activity indicates the increasing use of GenAI in the initial access and delivery stages of malware.”

Finally, hackers appear to be creating GitHub repositories advertising video game cheat and modification tools in order to deploy the Lumma Stealer malware using a .NET dropper.

VIP Keylogger 0bj3activity malware
Malicious code in images distributes VIP Keylogger & 0bj3ctivity malware

Malware protection

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install malware.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.

See also: WP3.XYZ malware: Adds fraudulent administrators to 5,000+ WordPress sites

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS