Threat Advisory

XWorm Malware Exploits Follina Vulnerability in New Wave of Attacks

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers have been actively tracking an ongoing attack campaign known as MEME#4CHAN. This campaign employs an unconventional approach, utilizing meme-filled PowerShell code and heavily obfuscated XWorm payloads to infect its targets. The MEME#4CHAN campaign employs a unique attack chain that combines PowerShell and JavaScript execution originating from a malicious Word document file. The CSharp code execution within the main PowerShell script delivers the final payload, ultimately executing XWorm v3.1.[/subscribe_to_unlock_form]

Summary:

Researchers have been actively tracking an ongoing attack campaign known as MEME#4CHAN. This campaign employs an unconventional approach, utilizing meme-filled PowerShell code and heavily obfuscated XWorm payloads to infect its targets. The MEME#4CHAN campaign employs a unique attack chain that combines PowerShell and JavaScript execution originating from a malicious Word document file. The CSharp code execution within the main PowerShell script delivers the final payload, ultimately executing XWorm v3.1.[emaillocker id="1283"]

The attack typically begins with a phishing email, often mimicking a fake hotel reservation scheme. The attackers aim to entice recipients into opening the attached phishing document, which triggers the initial code execution phase. The lure attachments are designed to create a sense of urgency, masking any suspicious requests. The phishing campaign targeted a German manufacturing company and sent phishing emails to a small German hospital clinic, suggesting a wider range of targets beyond just hotels. Examining one specific document in the attack chain, researchers find a Microsoft Word attachment named "Details for booking.docx." Upon opening the document, a prompt appears asking the user if they want to update the document with externally linked files. Clicking on either prompt closes the pop-up, revealing stolen images of a bank debit card and a driver's license, both seemingly belonging to French individuals. Notably, the phishing document does not contain macros or discernible p-code, indicating that macro execution is not the attack vector.

Execution Flow

The document used a known vulnerability (CVE-2022-30190) to embed external objects within the .docx file. A shape object in the document footer used the footer relationship file to fetch external objects, including an empty MS document file and a Blogspot URL. Another URL referenced an "atom.xml" file on Usr files, which redirected to another URL and downloaded a PowerShell script. The PowerShell script was partially obfuscated and contained a deobfuscation function named "£££" used to decode variables later in the script. The script performs various actions such as stopping processes, creating a directory for malware staging, disabling AMSI, modifying registry keys, adding defender exclusions, creating a new local user, and disabling the Windows Firewall. It also includes obfuscated variables with encoded strings that are decoded and used for executing additional PowerShell and JScript code. The JScript code is saved to disk and achieves persistence through a scheduled task. Additionally, the CSharp script contains heavily obfuscated .NET binaries that are injected into processes.

Throughout the attack chain, the attackers utilize obfuscation techniques to evade detection and execute their malicious payloads. By analyzing the campaign and understanding its tactics, organizations can enhance their defenses against similar threats and protect their systems and data.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/05/xworm-malware-exploits-follina.html

[/emaillocker]
crossmenu