Monday, March 3, 2025
HomeComputer SecurityHackers Launching a Fast-changing Malware Attack using .DOC Extention via Malspam...

Hackers Launching a Fast-changing Malware Attack using .DOC Extention via Malspam Emails

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malware that rapidly changing its sophisticated behavior in order to escape from the email security protection and infection the victims.

It’s very common that threat actors spreading countless malware via email campaigns, at the same time email security providers are keep fighting with them to block and terminate it.

But attackers using sophisticated techniques to evade security detection leads to increase the success ratio of the infection.

In this case, malspam emails are being sent to the targeted victims using automatically downloads a Word template using a .doc extension.

Unlike many attacks that use a single pattern with slight customizations, this attack uses a variety of different subject lines, email content, email addresses, display name spoofs, and destination URLs.

Also Attackers masquerading as a confirmation on a paid invoice that fooled users to click and open it to initiate the infection process.

Mostly attackers spoofing the email address to send the malspam email that contains a malicious link that points back to a compromised website where the malware will be ready to infect the system.

Also Read: Certified Advanced Persistent Threat Analyst online course

According to greathorn “Initially, this attack pattern identified  at 12:24pm on Wednesday, February 20th, the attack has (so far) consisted of three distinct waves, each wave corresponding with a different destination URL, one at 12:24pm ET, one 2:05pm ET, and a third at 2:55pm ET, suggesting an attack pattern that anticipated and planned for relatively quick shutdowns of the destination URLs. “

Cybercriminals mainly using many of the compromised accounts for phishing emails to target the victims especially the corporate employees.

“A small handful of attacks were highly targeted, appearing to be from another employee at the recipient’s organization and with customized subject and display names”.

GreatHorn researchers continuously monitoring this malware and its new attack pattern and provide additional information and remediation support.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

OceanLotus(APT32) Threat Actor Group Deliver KerrDown Malware Via Word Document and RAR Archive

Qealler – Heavily Obfuscated JAR-based Password Stealer Malware Delivered Through Invoice-related Files

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Chinese Hackers Breach Belgium State Security Service as Investigation Continues

Belgium’s State Security Service (VSSE) has suffered what is being described as its most...

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...