Hackers Using Microsoft Publisher File To Deliver Dangerous FlawedAmmyy RAT Targeting Banks

A new campaign using Weaponized Microsoft Publisher File(.pub) to deliver the FlawedAmmyy RAT. The FlawedAmmyy RAT is a backdoor tool that gains remote access to the attacker.

Security researchers from Trustwave spotted the Email campaign subjected “Payment Advice” with Microsoft Office Publisher file attached.

Once the .pub file is opened it asks the victim’s to Enable Macros, the macro script triggers Document_Open() event which opens the file and once the file is opened it access the URL that located in the Tag Property and executes a downloaded file.

At the time of analysis the URL was not active, but with further analysis, it was identified that the URL was used to download the self-extracting archive that contains the FlawedAmmyy RAT.

The FlawedAmmy RAT functions as follows
Remote Desktop control
File system manager
Proxy support
Audio Chat

With further analysis in the Cuckoo Sandbox, researchers confirmed that the backdoor accessed a certain IP related to FlawedAmmyy. It transfers the information such as id”, “os”, “names” and credentials from the victim’s machine to attacker’s server.

Researchers said this campaign is unusual and it was originated from the infamous notorious Necurs botnet. The campaign was small and it particularly targets domains belonging to banks.

With the previous campaign, attackers deliver FlawedAmmyy RAT via Weaponized Microsoft Word and PDF Attachments to spy victims device and steal the sensitive information Remotely.

Also Read

Beware of FlawedAmmyy-RAT that Steals Credentials and Record Audio Chat

Beware !! Hackers Deliver FlawedAmmyy RAT via Weaponized Microsoft Word and PDF Documents

New KeyPass Ransomware Actively Attacking Around the World To Encrypt the Victim Files

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Millions Of IoT Devices Vulnerable To Attacks Leads To Full Takeover

Researchers discovered four significant vulnerabilities in the ThroughTek Kalay Platform, which powers 100 million IoT-enabled devices. Notably, ThroughTek Kalay's influence…

14 hours ago

Apple Has Terminated 370 Million+ Developer & Customer Accounts

The App Store will close over 370 million developer and customer accounts in 2023. Apple takes this move to fight…

20 hours ago

VirusTotal’s Crowdsourced AI Initiative to Analyze Macros With Word & Excel Files

VirusTotal has announced a major change to its Crowdsourced AI project: it has added a new AI model that can…

22 hours ago

Vmware Workstation & Fusion Flaws Let Attackers Execute Arbitrary Code

Multiple security flaws affecting VMware Workstation and Fusion have been addressed by upgrades published by VMware. If these vulnerabilities are…

22 hours ago

QakBot Malware Exploiting Windows zero-Day To Gain System Privileges

In April 2024, security researchers revisited CVE-2023-36033, a Windows DWM Core Library elevation of privilege vulnerability that was previously discovered…

22 hours ago

Nissan Data Breach – 53,000+ Employees Data Stolen

Nissan says that the personal information of more than 53,000 workers has been stolen. The huge automaker is now taking…

23 hours ago