Cyber Security News

Beware Of Malicious SharePoint Notifications Delivering Xloader Malware

A sophisticated phishing campaign exploiting fake Microsoft SharePoint notifications to distribute the Xloader malware.

This malicious operation, recently intercepted by Sublime Security, highlights the growing threat of cybercriminals leveraging legitimate platforms to bypass traditional defenses.

The attack begins with a deceptive email mimicking a legitimate SharePoint file-sharing notification. The email includes an “Open files” link, complete with authentic-looking Microsoft branding and logos.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

Upon clicking the link, victims are directed to a malicious .zip file hosted outside SharePoint. This file contains an executable disguised as a document, which ultimately delivers the Xloader malware.

Sublime’s detection systems flagged this email as malicious due to several indicators:

  • Brand impersonation: The email used Microsoft’s logo and a fake SharePoint template.
  • Suspicious links: The embedded URL is redirected to a non-SharePoint domain hosting a malicious file.
  • Sender anomalies: The sender failed SPF (Sender Policy Framework) authentication, and the domain did not match legitimate Microsoft services.
  • Credential theft tactics: The email language aimed to deceive users into divulging sensitive information.

Xloader: A Dangerous Payload

Xloader, a rebranded version of the Formbook malware, is an advanced information stealer targeting Windows and macOS systems.

It can harvest user credentials, record keystrokes, capture screenshots, and steal data from browsers and email clients.

Xloader employs obfuscation techniques and multiple layers of encryption to evade detection, making it particularly challenging for security tools to identify.

In this case, Sublime’s analysis revealed that the malware was delivered through a complex chain involving obfuscated code, AutoIT scripts, shellcode injections, and process hijacking.

Researchers identified strong links between this attack’s initial loader component and TrickGate, another known malware loader.This campaign exemplifies attackers exploiting trusted platforms like SharePoint to disguise their malicious activities.

By leveraging legitimate services for phishing attacks, cybercriminals can bypass security filters and increase the likelihood of success.

Such tactics are part of a broader trend known as “living-off-trusted-sites” (LOTS), where attackers use familiar platforms to blend in with normal network traffic.

To mitigate risks from such attacks:

  1. Verify emails: Be cautious of unexpected file-sharing notifications, especially from unknown senders.
  2. Inspect links: Always check URLs for legitimacy before clicking.
  3. Enable multi-factor authentication (MFA): Add an extra layer of security to accounts.
  4. Educate employees: Conduct regular training on recognizing phishing attempts.
  5. Deploy robust security solutions: Use advanced email filtering and endpoint protection tools capable of detecting sophisticated threats.

As phishing campaigns grow more sophisticated, vigilance and proactive measures are essential to safeguard sensitive information and prevent breaches.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago