[DIYbio] Microsoft: “massive” PC hacking campaign used COVID-19, Excel files

https://www.slashgear.com/microsoft-massive-pc-hacking-campaign-used-covid-19-excel-files-22621689/

https://www.techspot.com/news/85356-microsoft-warns-massive-phishing-campaign-leveraging-excel-40.html

There are reports of a security attack


In brief: Microsoft's Security Intelligence team is warning of a massive phishing campaign, apparently parading around with a Covid-19 theme -- which seems especially malicious given the current state of events. As ever, be wary of emails you receive. Doubly so as phishing attempts get more modern.

The phishing campaign, as detailed by Microsoft's Security Intelligence team via Twitter, has been circulating since at least May 12th and comes with a Covid-19 lure to bait users into opening the email and accompanying attachment.

"We're tracking a massive campaign that delivers the legitimate remote access tool NetSupport Manager using emails with attachments containing malicious Excel 4.0 macros. The Covid-19 themed campaign started on May 12 and has so far used several hundreds of unique attachments," said Microsoft's Security Intelligence team through several tweets.


The emails claim to originate from The Johns Hopkins Center with titles like "WHO COVID-19 SITUATION REPORT." The emails contain attached Microsoft Excel files alleged to contain statistics on Covid-19 cases, and if opened, will use Excel 4.0 macros to install and run NetSupport Manager. While NetSupport Manager is a legitimate tool for remote control and desktop access, Microsoft claims it's known to be abused by attackers to run code on compromised machines.

From there, the NetSupport RAT (Remote Access Tool) connects to a C2 server to administer more commands, and also runs "several .dll, .ini, and other .exe files, a VBScript, and an obfuscated PowerSploit-based PowerShell script."

Microsoft's Security Intelligence Team notes that it has been seeing a steady increase in the use of Exel 4.0 macros deployed in malicious campaigns. And since April, the team has been seeing malicious Exel 4.0 macros combined with Covid-19 lures to slip under potential victims' radars.

--
-- You received this message because you are subscribed to the Google Groups DIYbio group. To post to this group, send email to diybio@googlegroups.com. To unsubscribe from this group, send email to diybio+unsubscribe@googlegroups.com. For more options, visit this group at https://groups.google.com/d/forum/diybio?hl=en
Learn more at www.diybio.org
---
You received this message because you are subscribed to the Google Groups "DIYbio" group.
To unsubscribe from this group and stop receiving emails from it, send an email to diybio+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/diybio/778d973c-0ca2-4c8c-a9b2-123645fdb35f%40googlegroups.com.

  • Digg
  • Del.icio.us
  • StumbleUpon
  • Reddit
  • RSS

0 comments:

Post a Comment