Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Belarus -related ghosts uses macros Excel, which contains macro to deploy malware
Global Security

Belarus -related ghosts uses macros Excel, which contains macro to deploy malware

AdminBy AdminFebruary 25, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 25, 2025Red LakshmananMalicious software / cyber -beno

Opposition activists in Belarus, as well as Ukrainian military and government organizations are the purpose of a new company that uses documents that are involved Picassoloader.

The cluster threats are evaluated as an extension of a long -standing company installed by an actor erected in Belarus know To match the Russian interests of security and the promotion of stories criticized by NATO.

Cybersecurity

“The company has been preparing since July-August 2024 and entered the active phase in November-December 2024,”-Researcher Sentinelone Tom Hegel – Note In a technical report that is shared with Hacker News. “The latest samples of malware and infrastructure activity (C2) (C2) show that the operation remains active in recent days.”

The starting point of the attack chain analyzed by cybersecurity company is the general document of Google Drive, which came from the account named Vladimir Nikifarech and accepted the RAR archive.

The rats file includes a malicious book Excel, which when opening the enchanting macro when the future victims allow you to launch macros. Macros continues to write the dll file, which eventually opens the way for a simplified version Picassoloader.

The next step in the system display the Exceel Excel file, while the background additional useful loads are loaded into the system. Recently in June 2024 this approach was used To deliver the cobalt after operation.

Sentinelone said she also discovered other Excel armed documents that carry baits with Ukraine’s theme to get an unknown malicious second -stage software from a remote URL (“Sciencealert (.) Store”) in the form of a seemingly harmless image JPG, technology, technique, technique, technique, technique Known as stegography. URL -Dour is more unavailable.

Cybersecurity

In another case, the Excel document registered BOOBY is used to deliver DLL called Libcmd, which is designed to launch cmd.exe and connect to Stdin/Stdout. It is directly loaded in memory in the form of .NET and executed.

“During 2024, the ghost repeatedly used the combination of Excel workbooks containing vba macro containing macro containing macro, and dropped built -in .net Downloaders, embarrassed. Confuserexsaid Hegel.

“While Belarus is not actively involved in military campaigns in the war in Ukraine, cyber -defeat actors associated with this do not have a spanning reservation against Ukrainian purposes.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.