Monday, July 22, 2024
EHA

Beware!! Hackers Now Spreading Dangerous FlawedAmmyy Malware Through PDF & IQY File

Cyber criminals now using IQY Files as a new technique for spreading dangerous FlawedAmmyy malware which is a dangerous backdoor tool that provides remote access to the attacker.

Attacker nowadays using new sophisticated techniques to compromise the targets by evading the security software and keep increasing the compromise success ratio.

Recently attackers using Weaponized Microsoft Publisher File(.pub)Microsoft Word and PDF Documents to deliver the FlawedAmmyy RAT.

Unlike previous infection Word document, Script, JAVA files and the current method of infection are used by new IQY file type an Excel Web Query file that is used to download data from the internet.

The targeted FlawedAmmyy malware campaigns have affected the banking sector and automotive industries.

FlawedAmmyy Malware Infection Process

Attackers initially using spam or spear phishing email campaign that contains attached IQY file and PDF file.

A body of the mail content prompt victims to click and open the attached PDF file that drops embedded IQY file.

A script that works along with the PDF file helps to export the IQY files from PDF using a function called “exportDataObject”  and the file export process continue by display a  ‘open file’ dialog box.

According to QuickHeal research, The script inside of the PDF file contains “cName” parameter is a required input and the specific file attachment that will be exported. A nLaunch value of “2” directs acrobat to save the file attachment to a temporary file and then asks the operating system to open it. This is how the code is used to open the attachment file in PDF.

Once user click OK then the file will be opened in  .iqy files that will lead to retrieving the content from the URL in the file but user needs to enable the security checks.

After enabling the security concern checks then IQY file download at %temp% location of victim machine and executed and the PowerShell Process will begin.

Finally, the PowerShell script will download the exe files and execute the backdoor FlawedAmmyy that performs various malicious activities such as let attack allow to remotely control the machine, manages the files, captures the screen.

IoCs

13cc8c748ab6beab2b942a9d04679511

839e9a3ecec7e8f735875ec65f1466e0

47205fbbb191dbcab606007fd7612ba7

61fe083a43cb0c520f38537744f9ac83

Website

Latest articles

SonicOS IPSec VPN Vulnerability Let Attackers Cause Dos Condition

SonicWall has disclosed a critical heap-based buffer overflow vulnerability in its SonicOS IPSec VPN....

Hackers Registered 500k+ Domains Using Algorithms For Extensive Cyber Attack

Hackers often register new domains for phishing attacks, spreading malware, and other deceitful activities. Such...

Hackers Claim Breach of Daikin: 40 GB of Confidential Data Exposed

Daikin, the world's largest air conditioner manufacturer, has become the latest target of the...

Emojis Are To Express Emotions, But CyberCriminals For Attacks

There are 3,664 emojis that can be used to express emotions, ideas, or objects...

Beware Of Fake Browser Updates That Installs Malicious BOINC Infrastructre

SocGholish malware, also known as FakeUpdates, has exhibited new behavior since July 4th, 2024,...

Data Breach Increases by Over 1,000% Annually

The Identity Theft Resource Center® (ITRC), a nationally recognized nonprofit organization established to support...

UK Police Arrested 17-year-old Boy Responsible for MGM Resorts Hack

UK police have arrested a 17-year-old boy from Walsall in connection with a notorious...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles