Sunday, April 6, 2025
HomeCyber AttackNew APT Actor240524 Weaponizing Official Documents To Deliver Malware

New APT Actor240524 Weaponizing Official Documents To Deliver Malware

Published on

SIEM as a Service

Follow Us on Google News

A new APT group, dubbed Actor240524, launched a spear-phishing campaign targeting Azerbaijani and Israeli diplomats on July 1, 2024, where the attackers employed a malicious Word document containing Azerbaijani-language content disguised as official documentation to lure victims. 

The attack indicates a potential focus on disrupting the Azerbaijan-Israel relationship, as the group leverages new Trojan programs, ABCloader and ABCsync, to steal sensitive data and remains undetected through various countermeasures. 

Decoy Document Used by Actor 240524

An attack commences with a phishing document that, upon user interaction, executes embedded VBA code to decrypt and store a malicious payload as a seemingly benign .log file. 

- Advertisement - Google News

It acts as a loader, performs environment checks, evades analysis, and decrypts additional payloads, including a DLL. Subsequently, it loads the DLL, establishing a connection to a C2 server for remote command execution and control. 

Exiting the Process After Detecting Analysis Behavior

The ABCloader and ABCsync Trojans employ robust anti-analysis measures. Critical components, including strings and API calls, are encrypted to hinder static and sandbox analysis. 

Additionally, the Trojans actively check the process environment for debugging indicators, such as the BeingDebugged flag and NtGlobalFlag, as well as leveraging NtQueryInformationProcess to identify debugging states, thus thwarting dynamic analysis attempts. 

The techniques aim to identify debugging environments by analyzing system characteristics and process attributes.

Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Access

Hardware breakpoint detection, screen resolution analysis, process count enumeration, and permission verification collectively assess the execution context for anomalies indicative of virtualized or sandboxed environments. 

Enumerating All Monitors in the System

The attack payloads “ABCloader” and “ABCsync” employ anti-debugging measures, encrypted communication, and registry manipulation to establish persistence and remote control, suggesting an advanced, under-development threat actor. 

While the Trojan, ABCsync, uses UDP for encrypted communication with a C2 server, employing AES-256 CBC for data protection. 

It executes remote shells, manipulates files, and exfiltrates data through pipe communication, receiving command-based instructions from the C2, which exhibits characteristics of a work-in-progress with detailed, sequential commands suggesting a complex control end. 

According to NSFOCUS Security Labs, by leveraging system information, it establishes pipes for shell execution, reads and writes files, and includes error handling and system version detection mechanisms.

System Registry Operations

A malicious actor employs a multi-stage attack. synchronize.exe, a loader similar to ABCloader, removes its own encryption for persistence. vcruntime190.dll and vcruntime220.dll hijack legitimate system components, LanguageComponentsInstaller.dll and Windows.UI.FileExplorer.dll, respectively, to execute synchronize.exe, ensuring its continued presence. 

The decoy document, iden.doc, with hash 1ee73b17111ab0ffb2f62690310f4ada, likely serves as an initial infection vector, while the C2 server, 185.23.253.143:36731, is the command-and-control endpoint for further malicious operations. 

Download Free Cybersecurity Planning Checklist for SME Leaders (PDF) – Free Download

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM)...

Beware! Fake Unpaid Tolls Messages Used in Phishing Attack to Steal Login Credentials

A surge in phishing text messages claiming unpaid tolls has been linked to a...