Friday, May 2, 2025
HomeBackdoorHackers Distributing PowerShell-based Backdoor Via MS Office document That Shares Stolen Data...

Hackers Distributing PowerShell-based Backdoor Via MS Office document That Shares Stolen Data Via C&C Sever

Published on

SIEM as a Service

Follow Us on Google News

Researchers observed a new Powershell based backdoor via Microsoft office document that infects similar to MuddyWater threat actor hacking tools to steal victims sensitive data and share it via C&C server to the attacker.

MuddyWater is a widely known cyber crime group and they active since 2017 and performs various  PowerShell script attacks on private and government entities. also it launches the same attack on other countries like Turkey, Pakistan, and Tajikistan in March 2018.

Newly discovered Powershell based backdoor contains many similar activities same as Muddywater previous campaign and it distributed via weaponized Word documents named Raport.doc or Gizli Raport.doc.

- Advertisement - Google News

These malicious documents have been uploaded from Turkey in virustotal and it drops backdoor which is written in PowerShell as MuddyWater’s known POWERSTATS backdoor.

Also in a new method of attack, Attackers using API of a cloud file hosting provider for Command & Control communication and share the stolen data or provide compromised system access to the attacker.

PowerShell-based Backdoor Infection Process

A malicious attachment sending via mail looks like a phishing document along with the logo that indicates the Turkish government organizations that help attackers to disguise users into believing the documents are legitimate.

Initially, it notifies users as it is an old version and enables the macro to update the new version of the document where the point infection process starts.

  Fake Office document tries to get the user to enable malicious macros

This macro’s using base52 which is rarely used by the sophisticated threat actors which are used to encode their backdoor.

Later a .dll file & a .reg file dropped into %temp% directory once the users enabled the macros.

“C:\Windows\System32\cmd.exe” /k %windir%\System32\reg.exe IMPORT %temp%\B.reg

After researchers analyse the PowerShell code, they conclude that it was highly obfusticated and contains encrypted code with variables named using English curse words.

Initially, the backdoor collects the various sensitive information including OS name, domain name, user name, IP address, and more which is similar that previously Muddywater used to collect.

According to Trend Micro research, difference between this and older Muddywater backdoors is that C&C communication is done by dropping files to the cloud provider. When we analyzed further, we saw that the communication methods use files named (hard disk serial number)> with various extensions depending on the purpose of the file .

This backdoor activity seems that it mainly targeting the Turkish government organizations related to the finance and energy sectors also if it belongs to Muddywater threat actor group then there is a chance to improve its functionality in future.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Managing Shadow IT Risks – CISO’s Practical Toolkit

Managing Shadow IT risks has become a critical challenge for Chief Information Security Officers...

Application Security in 2025 – CISO’s Priority Guide

Application security in 2025 has become a defining concern for every Chief Information Security...

Preparing for Quantum Cybersecurity Risks – CISO Insights

Quantum cybersecurity risks represent a paradigm shift in cybersecurity, demanding immediate attention from Chief...

Securing Digital Transformation – CISO’s Resource Hub

In today’s hyper-connected world, securing digital transformation is a technological upgrade and a fundamental...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Uncovers 42,000 Phishing Domains Tied to LabHost PhaaS Operation

The Federal Bureau of Investigation (FBI) has revealed the existence of 42,000 phishing domains...

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

Darktrace's Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been...

New WordPress Malware Disguised as Anti-Malware Plugin Takes Full Control of Websites

The Wordfence Threat Intelligence team has identified a new strain of WordPress malware that...