EXECUTIVE SUMMARY:
A campaign has been identified targeting individuals connected to the upcoming US-Taiwan Defense Industry Conference. This stealthy fileless attack employs social engineering tactics by distributing a malicious ZIP file masquerading as a legitimate conference registration form. The threat actor aims to trick users into executing a disguised LNK file that initiates a series of covert actions to compromise the victim's system.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A campaign has been identified targeting individuals connected to the upcoming US-Taiwan Defense Industry Conference. This stealthy fileless attack employs social engineering tactics by distributing a malicious ZIP file masquerading as a legitimate conference registration form. The threat actor aims to trick users into executing a disguised LNK file that initiates a series of covert actions to compromise the victim's system.[emaillocker id="1283"]
The attack begins with a ZIP archive containing an LNK file labeled as a PDF registration document. When executed, this stealthy fileless attack LNK file launches a series of commands to extract and execute both a lure PDF and a malicious executable. The executable is strategically placed in the startup folder to ensure persistence and is designed to download additional malicious content directly into memory, thus evading traditional detection methods. Utilizing .NET's Confuser for obfuscation, the malware employs advanced techniques to execute compiled C# code in memory without creating traceable files on disk. This method complicates detection efforts as it blends the malicious web requests with normal traffic, further hindering analysis and response.
In conclusion, this stealthy fileless attack highlights the increasing threats targeting key individuals associated with significant geopolitical events. By leveraging social engineering and advanced execution techniques, the threat actor aims to extract sensitive information while remaining undetected. The timing of this campaign, aligned with the US-Taiwan Defense Industry Conference, indicates a deliberate strategy to exploit the event for malicious purposes, underscoring the ongoing risks faced by organizations in the defense sector. This campaign serves as a reminder of the evolving tactics used by threat actors and the importance of vigilance against such stealthy fileless attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1140 | Deobfuscate/Decode Files or Information | |
| Command and Control | T1132 | Data Encoding |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
REFERENCES:
The following reports contain further technical details:
https://cyble.com/blog/stealthy-fileless-attack-targets-attendees-of-us-taiwan-defense-industry-event/