Articles New malware downloads Cobalt Strike via PNG image from...

New malware downloads Cobalt Strike via PNG image from Imgur

-

A security researcher using the Arkbird alias talked about a new malware that uses Word files with macros to download PowerShell scripts from GitHub. The script additionally downloads a legitimate file from the Imgur image hosting service to decode the Cobalt Strike payload on Windows systems.

As explained by Arkbird, the malware chain is delivered as an embedded macro in an outdated Microsoft Word file (* .doc). When you open a Word document, an inline macro runs, which runs powershell.exe and passes it the location of the PowerShell script hosted on GitHub. In a one-line script, there are instructions on how to download a real PNG file from the Imgur image hosting service.

While the image itself may be harmless, the pixel values ​​are used by the script when calculating the next stage payload. The payload calculation algorithm runs a foreach loop to iterate over the pixel values ​​in the PNG image and performs certain arithmetic operations to obtain ASCII functional commands.

The decoded script executes the Cobalt Strike payload. According to Arkbird, the payload does communicate with the C&C server through the WinINet module for further instructions.

Some experts have linked this type of malware to the MuddyWater APT group (also known as SeedWorm and TEMP.Zagros), first discovered in 2017 and mainly targeting Middle Eastern organizations.

Must read

28 dangerous extensions detected for Google Chrome and Microsoft Edge

Avast experts have discovered malware hidden in at least 28 third-party...

Why Is It Important To Have Intrusion Detection And Prevention ?

This article describes why detection and prevention of burglaries...

The risk is real: attacks on OT infrastructure

Previously, many believed that attacks on an isolated OT...

Gitpaste-12: Linux bot armed with a dozen exploits

Researchers at Juniper Networks have discovered a Linux scripting...

Saferwall : Open Source Malware Analysis

Saferwall is an open source malware analysis platform. It...

Network Vulnerability Assessment ? Why Should Every Company Do it at least once a Year !

Network vulnerability assessment analyzes a variety of network issues,...

Artificial Intelligence and Cyber Security

As artificial intelligence intrudes into the world of cybersecurity,...

You might also likeRELATED
Recommended to you