In order to distribute a previously undocumented backdoor named Rozena on Windows systems, an phishing campaign has recently been observed that leverages the recently disclosed Follina vulnerability.
The Microsoft Windows Support Diagnostic Tool (MSDT) is an application that is designed for remote code execution, resulting in a CVE-2022-30190 vulnerability that was published in May 2022.
A malicious external link can be embedded in a Microsoft Office document to trigger an exploit that will allow attackers to inject a malicious OLE object in the file and lure victims into clicking on the link or simply previewing the document.
Upon opening a weaponized document that contains a Discord CDN URL as a starting point, the document connects to a Discord CDN URL in order to retrieve an HTML file (“index.htm”) as the result of the latest attack chain observed by Fortinet.
This, in turn, summons a PowerShell command to begin the diagnostic utility, which, then downloads the next-stage payloads from the same CDN attachment space to complete the diagnostic process.
In the package there are two files – the Rozena implant (Word.exe) and a batch file (cd.bat) which are responsible for performing the following tasks and activities:-
By injecting shellcode into the file, the malware transmits a reverse shell request to the host (“microsofto.duckdns[.]org”) of the attacker. As a result, a Rozena backdoor to the compromised system is left open, allowing the attacker to control the monitoring system and capture information.
Files and Malware Used
According to the Fortinet report, Malicious Word documents are being used to spread malware exploiting the Follina flaw. By exploiting the following files, the attackers use social engineering techniques to exploit the vulnerability:-
Here, all these above-mentioned files were used by the threat actors as droppers to deploy malware on the victim’s device. And here below we have mentioned all the types of malware used:-
This critical vulnerability “CVE-2022-30190” could be exploited by threat actors in order to deliver malware via Word documents, thus creating an easy way for malware to spread.
As of June 14, 2022, Microsoft has already released a patch to address this issue. Moreover, FortiGuard’s cybersecurity analysts have strongly recommended that users should apply the patch immediately in order to prevent this vulnerability.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…