A multi-stage cyberattack effort originating from malicious LNK files has been detected, with the healthcare business as the target.
When the LNK file is executed, it initiates a PowerShell command that downloads and runs a number of additional payloads from a remote server, such as BAT files and PowerShell scripts.
“The attack involves the creation of an administrative account on the victim’s system and altering Remote Desktop settings to lower authentication requirements, simplifying unauthorized RDP access for the attacker,” Cyble Research and Intelligence Labs (CRIL) shared with Cyber Security News.
An anonymous group has continuously reappeared over the last 12 months with different luring themes and unchanged attack methods.
Ultimate Guide to Manage your SIEM Pricing -> Free Download
The attack, which is being tracked as HeptaX, primarily uses PowerShell and Batch scripts to take over vulnerable servers.
Initially, the downloaded PowerShell script creates a base URL that it uses to download additional stage payloads and deliver information. The initial function of the PowerShell script is to acquire the compromised system’s unique identifier (UID).
Further, the PowerShell script downloads a password-protected lure document from the remote server and launches it. This script mainly aims to assess the system’s User Account Control (UAC) configurations.
It does this by using the same registry checks that were used previously to determine whether UAC is activated and whether the administrator consent prompt is still active.
A new PowerShell script is launched after connecting to the server. This script has a number of features designed to communicate with the remote server, exfiltrate data, and reconnaissance systems.
“With all the collected information, User Account Control (UAC) disabled, and a new user account named “BootUEFI” created with administrative privileges, along with lowered authentication requirements for Terminal Services, the TAs can easily gain access to the compromised remote desktop”, researchers said.
Over the past year, this threat group has also been linked to previous campaigns that contain malicious files with names like:
Among the noteworthy files from this campaign is:
The variety of file names and themes indicate a broad targeting approach across several industries, implying that this gang customizes its campaigns to appeal to a range of victims.
Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…