Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro
#1
Information 
Quote:The Gamaredon threat group has given its post-compromise toolset a facelift with the addition of a new Visual Basic for Applications (VBA) macro. The VBA macro leverages compromised victims’ Microsoft Outlook email accounts to send spear-phishing emails to their contacts – rapidly widening the potential attack surface.
 
Researchers say, while abusing a compromised mailbox to send malicious emails is not a new technique, this is the first publicly documented case of an attack group using both an Outlook macro and an OTM file to do so. An OTM file stores macros that are written for Microsoft Outlook.
 
“In the last few months, there has been an increase in activity from this group, with constant waves of malicious emails hitting their targets’ mailboxes,” according to Jean-Ian Boutin, senior malware researcher with ESET, in a Thursday analysis. “The attachments to these emails are documents with malicious macros that, when executed, try to download a multitude of different malware variants.”

After the victim is initially compromised (typically via a spear-phishing email with a malicious attachment), malicious code is first delivered in a 7z self-extracting archive. 7z are compressed archive files created with 7-Zip open source software. The code runs a VBScript that first kills the victim’s Outlook process (if it is running), and then removes any security protections around VBA macro execution in Outlook by changing registry values.

Read more: https://threatpost.com/microsoft-outlook...ro/156484/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro - by silversurfer - 12 June 20, 07:51

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.4  Fixed a d...Kool — 10:40
Traffic Violation Scam Texts Now Use QR ...
A phishing campaig...harlan4096 — 09:34
Microsoft Begins Warning Users Ahead of ...
Microsoft has star...harlan4096 — 09:07
K-Lite Codec Pack 19.6.6/ 19.6.6 Update
Changes in 19.6.6 ...harlan4096 — 07:40
Intel shows Texture Set Neural Compressi...
TSNC Variant A del...harlan4096 — 07:39

[-]
Birthdays
Today's Birthdays
avatar (46)JamesZic
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>