Thursday, October 10, 2024
Homecyber securityHackers Exploiting Old Microsoft Office RCE Flaw to Deploy Agent Tesla Malware

Hackers Exploiting Old Microsoft Office RCE Flaw to Deploy Agent Tesla Malware

Published on

It has been reported that malicious individuals are utilizing a malware called Agent Tesla to target Microsoft Office users using versions affected by CVE-2017-11882 XLAM.

This malware is taking advantage of a remote code execution vulnerability in Equation Editor, which is present in Microsoft Office and known as CVE-2017-11882.

Remote code execution (RCE) is a type of cyberattack where an attacker uses a remote computer or network to execute malicious code without requiring user data.

- Advertisement - EHA

Sensitive information can be accessed remotely through a code execution vulnerability, without requiring physical network access by hackers.

It is important to be aware of spam emails that contain malicious attachments. Hackers often use this technique to inject harmful programs onto a user’s device.

Once the user downloads and opens the attachment, the malicious program is activated, potentially causing harm to the device and compromising sensitive information.

Spam with a malicious attachment
Spam with a malicious attachment

According to the Zscaler report, if a user downloads and views a malicious attachment on a vulnerable version of Microsoft Excel, the Excel file will connect to a negative location and start downloading other files without requiring any further action from the user.

Variable names in the VBS file are 100 characters long, which complicates the deobfuscation and analysis process. The JPG file contains a malicious Base64-encoded DLL.

After the JPG file is downloaded, the VBS file initiates the execution of a PowerShell executable. This executable then retrieves a DLL in Base64-encoded form from the image file. The DLL is subsequently decoded, and its malicious procedures are loaded.

PowerShell performs the main operation for reading and writing the registry. After this, the DLL injects a thread into the main function, which retrieves the Agent Tesla payload.

Agent Tesla attempts to install hooks for both the clipboard and keyboard to monitor and record every keystroke that the user types and collect data from the user’s copied information.

Agent Tesla employs a technique known as window hooking to monitor users’ keystrokes, mouse movements, and event messages. The function of the malicious actor ceases before the user can react.

A Telegram bot controls the threat actor who receives the data exfiltrated from the virus. To protect our information, we must keep ourselves informed about cyber threats and stay updated.

Latest articles

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Foxit PDF Reader Vulnerability Let Attackers Execute Arbitary Code

Researchers recently disclosed six new security vulnerabilities across various software, as one critical vulnerability...