Threat Advisory

Threat Actors Abuse MacroPack Framework to Deploy Disguised Malicious Payloads

Threat: Malicious Campaign
Targeted Region: China, Pakistan, Russia & U.S.
Targeted Sector: Technology & IT, Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have discovered a series of malicious Microsoft Office documents generated by the MacroPack framework were identified. These documents were uploaded from various countries, including China, Pakistan, Russia, and the U.S. MacroPack, originally designed for Red Team exercises, is now being utilized by threat actors to deploy various malicious payloads. The documents in question feature different lures and techniques but share common attributes linked to MacroPack.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have discovered a series of malicious Microsoft Office documents generated by the MacroPack framework were identified. These documents were uploaded from various countries, including China, Pakistan, Russia, and the U.S. MacroPack, originally designed for Red Team exercises, is now being utilized by threat actors to deploy various malicious payloads. The documents in question feature different lures and techniques but share common attributes linked to MacroPack.[emaillocker id="1283"]

The MacroPack framework generates VBA code with obfuscated elements to evade detection, including function and variable renaming, string encoding, and removal of comments. Discovered documents exhibit stages of execution before contacting command and control (C2) servers. Notably, documents from China and Pakistan delivered Havoc and Brute Ratel payloads, while Russian-origin documents utilized a variant of PhantomCore. These documents often include non-malicious VBA subroutines sourced from legitimate references, which may lower the suspicion level and help bypass anti-malware heuristics. Additionally, documents from the U.S. utilized a Markov Chain-based name generator to obfuscate their code further.

The use of MacroPack by malicious actors illustrates its potential for abuse beyond its intended Red Team applications. The documents analyzed demonstrate sophisticated evasion techniques and varied payloads, reflecting a broader trend of leveraging legitimate tools for malicious purposes. While no direct attribution to specific threat actors was possible, the patterns observed highlight the importance of vigilance against such threats. Organizations should ensure they are using updated Office versions and maintain robust detection capabilities to address evolving threats from tools like MacroPack.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution  T1059 Command and Scripting Interpreter
T1106 Native API
Persistence T1543 Create or Modify System Process
 Defense Evasion T1027 Obfuscated Files or Information
Collection T1074 Data Staged
Command and Control T1071 Application Layer Protocol
T1219 Remote Access Software
 Exfiltration  T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/red-team-tool-macropack-abused-in-attacks-to-deploy-brute-ratel/

[/emaillocker]
crossmenu