Threat Advisory

Electron-based Applications Gain Dynamic Script Execution Capability

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Projextor is a Trojanized productivity application that disguises itself as legitimate software, making it easy for users to trust and download without realizing they contain hidden malicious code. This threat campaign leverages the popularity of free productivity tools, which are often trusted by users who download them from websites with high-ranking search results. The malware uses Electron-based applications such as Kitchen Canvas, Food Formula, DocConvertWizard, and other PDF conversion tools under different names, each concealing the same malware beneath a working user interface.

The applications silently gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. To facilitate communication between the Chromium renderer process and privileged a script payload functionality, Electron uses a component known as a preload script. Executed before the renderer process is fully initialized, the preload script serves as a bridge between the browser environment and a script payload APIs, enabling application developers to selectively expose privileged functionality to web content.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Projextor is a Trojanized productivity application that disguises itself as legitimate software, making it easy for users to trust and download without realizing they contain hidden malicious code. This threat campaign leverages the popularity of free productivity tools, which are often trusted by users who download them from websites with high-ranking search results. The malware uses Electron-based applications such as Kitchen Canvas, Food Formula, DocConvertWizard, and other PDF conversion tools under different names, each concealing the same malware beneath a working user interface.

The applications silently gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. To facilitate communication between the Chromium renderer process and privileged a script payload functionality, Electron uses a component known as a preload script. Executed before the renderer process is fully initialized, the preload script serves as a bridge between the browser environment and a script payload APIs, enabling application developers to selectively expose privileged functionality to web content.[emaillocker id="1283"]

The applications are not fake; they do what they promise to do. The concern is that they also include functionality that allows additional JavaScript code to be loaded and executed at runtime, giving the application capabilities far beyond those expected of a productivity tool. These applications are part of the same campaign or were built from the same code base, but it is unclear if they were created or operated by the same threat actor.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.007 Command and Scripting Interpreter JavaScript
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Collection T1113 Screen Capture -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Defense Evasion B0029 Polymorphic Code
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Discovery E1082 System Information Discovery
Anti-Static Analysis E1027 Obfuscated Files or Information
Execution B0023 Install Additional Program

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu