Malware authors persistently seek novel approaches to exploit unsuspecting users in the active cyber threat landscape.
To easily locate all the available files, folders, and other items on your Windows system, Microsoft Windows OS offers an outstanding powerful tool known as the Windows search feature.
Unexplored by many, the “search-ms” URI protocol handler in Windows allows potent local and remote searches, but security researchers at Trellix warn of potential exploitation.
Cybersecurity researchers at Trellix Advanced Research Center revealed that this new attack technique exploits the “search-ms” URI protocol with JavaScript on websites and HTML attachments.
This expands the attack surface and not only that even also explores the “search” protocol as well.
Threat actors exploit the “search-ms” protocol to deceive users with emails, compromised websites, and disguised remote files to make them execute malicious code unknowingly.
Besides this, security analysts detected several phishing emails using the “search-ms” protocol to deliver a malicious payload, masked as urgent sales quotation requests.
Various attack variants involve emails with HTML/PDF attachments containing URLs to compromised websites using the ‘search-ms’ URI protocol handler, while embedded scripts in HTML files can also trigger the attack.
Once the link in the email or attachment is clicked, users get redirected to a website exploiting the “search-ms” URI protocol handler, revealing a suspicious script in the GET request for page.html:-
Experts uncover numerous PowerShell file variants in this investigation, comprising:-
The campaign deploys remote access trojans (RATs) like Async RAT and Remcos RAT to gain unauthorized control over infected systems, facilitating:-
The Remcos RAT employs null byte injection in its EXE payload to evade security products. The attacker employs a proactive approach, continuously updating files to avoid security product detection, and bypassing static signatures and known IoCs.
Security analysts found attacker-controlled file servers, some lacking authentication, posing a significant security risk by enabling easy access for further exploitation.
Here Below we have mentioned all the recommendations:-
Keep yourself informed about the latest Cyber Security News by following us on GoogleNews, Linkedin, Twitter, and Facebook.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…