Threat Advisory

OneDrive Pastejacking Campaign Executes Malicious PowerShell Script on Users

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An downloader campaign has been observed, targeting Microsoft OneDrive users through social engineering tactics. The campaign involves deceiving users into executing a PowerShell script, compromising their systems. The attack starts with an email that entices users to click on a button to fix a supposed DNS issue, leveraging a sense of urgency to prompt action.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

An downloader campaign has been observed, targeting Microsoft OneDrive users through social engineering tactics. The campaign involves deceiving users into executing a PowerShell script, compromising their systems. The attack starts with an email that entices users to click on a button to fix a supposed DNS issue, leveraging a sense of urgency to prompt action.[emaillocker id="1283"]

 

The campaign initiates through an email containing an .html file, which, when opened, displays a deceptive Microsoft OneDrive page. This page shows a file named "Reports.pdf" alongside an error message "Error 0x8004de86," prompting users to update the DNS cache manually. Clicking the "Details" button redirects to a legitimate Microsoft Learn page, while the "How to fix" button triggers a function call within an embedded .js script. This script instructs users to open the PowerShell terminal and execute a Base64 encoded command, which, once decoded, flushes the DNS, creates a folder, downloads and extracts files, and executes a malicious script using AutoIt3.exe. The campaign relies on creating a sense of urgency and manipulating users' emotions to prompt hasty actions.

 

This campaign highlights the persistent threat of social engineering attacks, which can bypass even robust security measures by exploiting human vulnerabilities. The impact of such attacks in enterprise environments can be devastating, leading to widespread network compromise, financial losses, and reputational damage. Continuous employee training, stringent security protocols, and international cooperation are essential to defend against these threats.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
 Execution T1059 Command and Scripting Interpreter
 T1203 Exploitation for Client Execution
T1053 Scheduled Task/Job
Defense Evasion T1140 Deobfuscate/Decode Files or Information
T1070 Indicator Removal
Credential Access  T1555 Credentials from Password Stores
Command and Control T1071 Application Layer Protocol

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/07/onedrive-phishing-scam-tricks-users.html

[/emaillocker]
crossmenu