HomeinetPhishing campaign steals business credentials

Phishing campaign steals business credentials

A ongoing phishing campaign targets French-speaking corporate environments with fake résumés that lead to the deployment of cryptocurrency miners and infostealers.

See also: Android malware targets Indian users through fake eChallan notifications

phishing campaign
Phishing campaign steals business credentials

The phishing campaign uses highly concealed VBScript files that masquerade as resume/CV documents, which are delivered via phishing emails. Once executed, the malicious software deploys a multifunctional tool that combines credential theft, data exfiltration, and Monero cryptocurrency mining for maximum profit.

The activity has been codenamed FAUX#ELEVATE by the cybersecurity firm. The campaign is notable for abusing legitimate services and infrastructure, such as Dropbox for load staging, Moroccan WordPress websites for hosting command and control (C2) configurations, and mail.ru's SMTP infrastructure to extract stolen browser credentials and desktop files.

This is an example of a living-off-the-land attack that raises the bar on how attackers can outsmart defense mechanisms and infiltrate a target's system without attracting much attention.

The original dropper file is a Visual Basic Script (VBScript) that, when opened, displays a fake error message in French, tricking recipients of the message into believing that the file is corrupted. However, in the background, the heavily disguised script performs a series of checks to evade sandboxes and enters a persistent User Account Control (UAC) loop that prompts users to run it with administrator privileges.

Importantly, out of the 224,471 lines of the script, only 266 lines contain actual executable code. The rest of the script is filled with useless comments with random English sentences, increasing the file size to 9.7 MB.

The malware also uses a domain connection gateway using WMI (Windows Management Instrumentation), ensuring that the payloads are delivered only to corporate machines, while independent home systems are completely excluded.

See also: Speagle malware: Abuse of Cobra DocGuard to steal data

Phishing campaign steals business credentials
Phishing campaign steals business credentials

Once the dropper gains administrator privileges, it disables security measures and covers its tracks by configuring exclusion paths in Microsoft Defender for all primary drive letters (from C to I), disabling UAC via a change in the Windows Registry and deleting itself.

The dropper is responsible for downloading two separate password‑protected 7‑Zip files hosted on Dropbox:

  • gmail2.7z, which contains various executables for data theft and cryptocurrency mining
  • gmail_ma.7z, which contains utilities for persistence and cleaning

Among the tools used to facilitate credential theft is a component that leverages the ChromElevator project to extract sensitive data from Chromium-based browsers by bypassing the encryption protections that are bound to the application (ABE). Other tools include:

  • mozilla.vbs, a VBScript malware for stealing Mozilla Firefox profiles and credentials
  • walls.vbs, a VBScript load to export desktop files
  • mservice.exe, a cryptocurrency miner XMRig that launches after retrieving the mining configuration from a compromised Moroccan WordPress site
  • WinRing0x64.sys, a legitimate Windows kernel driver used to unlock the full mining potential of the CPU
  • RuntimeHost.exe, a persistent Trojan component that modifies Windows Firewall rules and periodically communicates with a C2 server

The unique browser data is exfiltrated using two separate mail.ru sender accounts that share the same password via SMTP to another email address operated by the attacker.

See also: Espionage: MuddyWater targets diplomats and critical infrastructure

Phishing campaign steals business credentials

Once credential theft and exfiltration activities are completed, the attack chain initiates an aggressive cleanup of all installed tools in an effort to minimize the forensic analysis footprint, leaving only the miner and the Trojan behind. The FAUX#ELEVATE campaign shows a well-organized, multi-layered attack operation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS