HP Wolf Security has identified two campaigns where hackers hide malicious code in images and infect victims with the VIP Keylogger and 0bj3ctivity Stealer malware.

“ In both campaigns, the attackers hid malicious code in images they uploaded to archive[.]org, a website that hosts archives. They used the same .NET loader to install the final payloads ,” HP Wolf Security said in its Threat Insights Report for Q3 2024.
VIP Keylogger
The attacks begin with a phishing email with the subject line "Invoices and Purchase Orders." Recipients are asked to open malicious attachments, such as Microsoft Excel documents. When these documents are opened, a vulnerability in the Equation Editor (CVE-2017-11882) is exploited to download a VBScript file.
The script is designed to decode and execute a PowerShell script that retrieves an image hosted on archive[.]org and extracts a Base64-encoded code. This is then decoded into a .NET executable and executed.
See also: MikroTik botnet uses SPF DNS records to spread malware
The .NET executable serves as a loader to download the VIP Keylogger malware from a URL. It also allows its execution, which leads to the theft of various data from infected systems (keystrokes, clipboard contents, screenshots, and credentials).
0bj3ctivity Stealer malware
The second campaign, which is similar, also starts with phishing emails containing malicious archive files. These messages, which are presented as requests for offers, try to trick visitors into opening a JavaScript file within the archive . A PowerShell script is then executed .
The PowerShell script downloads an image from a remote server, parses the code, and executes the .NET loader (also used in the VIP Keylogger campaign). However, this attack chain ends up delivering the 0bj3ctivity Stealer malware.
HP Wolf Security has observed that hackers are also resorting to HTML smuggling to install the XWorm remote access trojan (RAT), via an AutoIt dropper.
See also: USA: FBI removes PlugX malware from thousands of computers
“In particular, the HTML files carried characteristics that suggest they were written with the help of GenAI,” HP said. “The activity indicates the increasing use of GenAI in the initial access and delivery stages of malware.”
Finally, hackers appear to be creating GitHub repositories advertising video game cheat and modification tools in order to deploy the Lumma Stealer malware using a .NET dropper.

Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install malware.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.
See also: WP3.XYZ malware: Adds fraudulent administrators to 5,000+ WordPress sites
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
Source: thehackernews.com
