EXECUTIVE SUMMARY
Researchers have several incidents involving the financially motivated threat group FIN7 were observed by. The group, known for its activities utilized malicious websites impersonating reputable brands to distribute malicious payloads. Notably, they leveraged sponsored Google Ads to lure users into downloading fake browser extensions, which were disguised as MSIX files, a Windows app packaging format.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have several incidents involving the financially motivated threat group FIN7 were observed by. The group, known for its activities utilized malicious websites impersonating reputable brands to distribute malicious payloads. Notably, they leveraged sponsored Google Ads to lure users into downloading fake browser extensions, which were disguised as MSIX files, a Windows app packaging format.[emaillocker id="1283"]
In the first case, users were lured into downloading fake browser extensions from malicious websites, triggering the execution of PowerShell scripts embedded within MSIX files. These scripts, upon execution, collected system information and communicated with command-and-control servers to download and execute the NetSupport RAT. Similarly, in the second case, a fake MSIX installer led to the installation of NetSupport RAT, followed by the deployment of additional malicious tools such as csvde.exe and svchostc.py. The threat actors utilized these tools for reconnaissance, persistence, and process injection, showcasing a modus operandi.
The incidents underscore the significance of exercising caution while interacting with online advertisements and downloading files from unknown sources. The deceptive use of signed MSIX files highlights the need for users to remain vigilant and verify file sources thoroughly. Despite being signed with seemingly legitimate company names, these files contained malicious payloads, emphasizing that certification does not guarantee safety. These observations emphasize the ongoing threat posed by sophisticated threat actors and the importance of robust cybersecurity practices.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1087 | Account Discovery |
| Collection | T1560 | Archive Collected Data |
| Command and Control | T1071 | Application Layer Protocol |
| T1105 | Ingress Tool Transfer | |
| T1573 | Encrypted Channel |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/05/fin7-hacker-group-leverages-malicious.html