Wednesday, September 18, 2024
HomeMalwareHackers Distributing Malware Via Weaponized PDF & MS Word Version of New...

Hackers Distributing Malware Via Weaponized PDF & MS Word Version of New Zealand Terror Suspect’s Manifesto

Published on

Cyber Criminals launching a new malware via weaponized PDF & MS Word Version of New Zealand terror suspect’s manifesto.

Researchers noticed 8chan, an imageboard website composed of user-created boards contains several posts that link to a manifesto, allegedly authored by the terror suspect of New Zealand terror attack.

These Manifesto contain several version of PDF and Word Documents and these documents were circulated in the underground forums since the document has gone viral on the internet.

- Advertisement - EHA

In this case, attackers taking advantage of this manifesto propaganda to distribute a trojanized version of the manifesto Titled ‘The Great Replacement’,

Pages from the Weaponized Manifesto.

The Weaponized version of the manifesto resembles content from the original manifesto with several other future.

According to Blue Hexagon Research, “The metadata from the original manifesto states the author as the name of the alleged suspect who has been arrested in connection with the terror attack, whereas the author info in the weaponized trojan says it was created by the author ‘Maori’ (a name for the indigenous people of New Zealand). “

Weaponised PDF & MS Word Version

Once users click the malformed PDF & MS word version, an obfuscated VBA script gets executed and download the next stage of payload.-‘Haka.exe’.

The second stage of the payload is a PE file that is limited to overwriting the Master Boot Record (MBR) with a message displayed to force restart the system.

After the successful execution, the system gets restarted and displays the following massage.

Based on the attack scenario, there is no motivation behind this malware other than being disruptive. but this incident can be abused by other sophisticated malware by leveraging these weaponized documents.

Learn: Complete Malware Analysis Course- Advance Malware Analyst Bundle

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Hackers Launching Weaponized Word Document to Push Emotet & Qakbot Malware

OceanLotus(APT32) Threat Actor Group Deliver KerrDown Malware Via Word Document and RAR Archive

Hackers Delivering Redaman Banking Malware Disguising as a PDF Document

New Marap Malware Targeting Financial Institutions Via Microsoft Office and PDF Documents

Beware !! Hackers Deliver FlawedAmmyy RAT via Weaponized Microsoft Word and PDF Documents

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actor Allegedly Selling Bharat Petroleum Database

A threat actor has allegedly put up for sale a database belonging to Bharat...

Chrome 129 Released with Fix for Multiple Security Vulnerabilities

The Chrome team has officially announced the release of Chrome 129, which is now...

VMware vCenter Server Vulnerability Let Attackers Escalate Privileges

VMware has issued a critical security advisory (VMSA-2024-0019) addressing two significant vulnerabilities in its...

CISA Warns of Windows MSHTML & Progress WhatsUp Gold Flaw Exploited Widely

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding two...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Hackers Exploiting Selenium Grid Tool To Deploy Exploit Kit & Proxyjacker

Two campaigns targeting Selenium Grid's default lack of authentication are underway, as threat actors...

North Korean Hackers Attacking LinkedIn Users to Deliver RustDoor Malware

North Korean hackers have been identified as targeting LinkedIn users to deliver sophisticated malware...

Crimson Palace Returns With New Hacking Tolls And Tactics

Cluster Bravo, despite its brief initial activity, subsequently targeted 11 organizations in the same...