Friday, February 21, 2025
Homecyber securityNew Phishing Attack Hijacks Email Thread to Inject Malicious URL

New Phishing Attack Hijacks Email Thread to Inject Malicious URL

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new campaign delivering DarkGate and PikaBot that employs strategies similar to those employed in QakBot phishing attempts.

This operation sends out a large number of emails to a variety of industries, and because the malware transmitted has loader capabilities, recipients may be vulnerable to more complex threats such as reconnaissance malware and ransomware.

“These include hijacked email threads as the initial infection, URLs with unique patterns that limit user access, and an infection chain nearly identical to what we have seen with QakBot delivery,” Cofense Intelligence stated in a report shared with Cyber Security News.

Infection Chain 

The tactics, techniques, and procedures (TTPs) used in this campaign make it a high-level threat because they allow phishing emails to reach their targeted targets, and the malware they distribute has sophisticated capabilities.

A hijacked email thread is used at the start of the campaign to trick customers into visiting a malicious URL with further layers. This restricts access to the malicious payload to users who match certain criteria provided by the threat actors (location and web browser).

This URL downloads a ZIP archive containing a JS file known as a JS Dropper, a JavaScript program that connects to another URL to download and execute malware. At this point, the DarkGate or PikaBot malware has successfully infected a victim.

Infection chain used in the campaign

The most prominent feature of these malware families is their ability to deliver additional payloads once they are successfully planted on a user’s PC.

Advanced crypto mining software, reconnaissance tools, ransomware, or any other malicious file the threat actors choose to install on a victim’s computer might be delivered via a successful DarkGate or PikaBot infection.

Document
Free Webinar

Live API Attack Simulation Webinar

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked. The session will cover: an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

“Threat actors disseminate the phishing emails through hijacked email threads that may be obtained from Microsoft ProxyLogon attacks (CVE-2021-26855). This is vulnerability on the Microsoft Exchange Server that allows threat actors to bypass authentication and impersonate admins”, researchers explain.

Figure 3: Real hijacked email thread example that delivered PikaBot (ATR 351964).
Real hijacked email thread that delivered PikaBot

The email’s malicious URL has a distinct pattern similar to those found in QakBot phishing attacks. Threat actors have added layers to these URLs to restrict access to the malicious file they are delivering, making them more sophisticated than your typical phishing URL.

Hence, employees should be aware that this kind of threat exists, as the campaign’s threat actors have skills that go beyond those of a typical phisher.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...