EXECUTIVE SUMMARY
An downloader campaign has been observed, targeting Microsoft OneDrive users through social engineering tactics. The campaign involves deceiving users into executing a PowerShell script, compromising their systems. The attack starts with an email that entices users to click on a button to fix a supposed DNS issue, leveraging a sense of urgency to prompt action.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
An downloader campaign has been observed, targeting Microsoft OneDrive users through social engineering tactics. The campaign involves deceiving users into executing a PowerShell script, compromising their systems. The attack starts with an email that entices users to click on a button to fix a supposed DNS issue, leveraging a sense of urgency to prompt action.[emaillocker id="1283"]
The campaign initiates through an email containing an .html file, which, when opened, displays a deceptive Microsoft OneDrive page. This page shows a file named "Reports.pdf" alongside an error message "Error 0x8004de86," prompting users to update the DNS cache manually. Clicking the "Details" button redirects to a legitimate Microsoft Learn page, while the "How to fix" button triggers a function call within an embedded .js script. This script instructs users to open the PowerShell terminal and execute a Base64 encoded command, which, once decoded, flushes the DNS, creates a folder, downloads and extracts files, and executes a malicious script using AutoIt3.exe. The campaign relies on creating a sense of urgency and manipulating users' emotions to prompt hasty actions.
This campaign highlights the persistent threat of social engineering attacks, which can bypass even robust security measures by exploiting human vulnerabilities. The impact of such attacks in enterprise environments can be devastating, leading to widespread network compromise, financial losses, and reputational damage. Continuous employee training, stringent security protocols, and international cooperation are essential to defend against these threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information |
| T1070 | Indicator Removal | |
| Credential Access | T1555 | Credentials from Password Stores |
| Command and Control | T1071 | Application Layer Protocol |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/07/onedrive-phishing-scam-tricks-users.html