Threat Advisory

Hackers use PowerPoint files for 'mouseover' malware delivery

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Russian affiliated threat actor APT28 (aka Fancy Bear, TSAR Team, Pawn Storm, Sednit) has developed a new way to infect computers with Graphite malware, that only requires a potential victim to hover over a hyperlink within a PowerPoint presentation slide without requiring a user to click on a link. The threat actor delivers a ppt to a victim related to any government scheme or notification to lure them. Inside ppt, there is a hyperlink or a Zoom Interpretation option. When the victim mouses over the text it results in PowerPoint executing a PowerShell script infecting the victim’s device.[/subscribe_to_unlock_form]

Summary:

Russian affiliated threat actor APT28 (aka Fancy Bear, TSAR Team, Pawn Storm, Sednit) has developed a new way to infect computers with Graphite malware, that only requires a potential victim to hover over a hyperlink within a PowerPoint presentation slide without requiring a user to click on a link. The threat actor delivers a ppt to a victim related to any government scheme or notification to lure them. Inside ppt, there is a hyperlink or a Zoom Interpretation option. When the victim mouses over the text it results in PowerPoint executing a PowerShell script infecting the victim’s device.[emaillocker id="1283"]

Document lure used in new campaign using Graphite malware

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/hackers-use-powerpoint-files-for-mouseover-malware-delivery/

(Kindly exclude this link in the advisory mail)

https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/

[/emaillocker]
crossmenu