Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hackers are using Microsoft MSC files to deploy hidden backdoors during attacks in Pakistan
Global Security

Hackers are using Microsoft MSC files to deploy hidden backdoors during attacks in Pakistan

AdminBy AdminDecember 17, 2024No Comments3 Mins Read
Obfuscated Backdoor
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 17, 2024Ravi LakshmananCyber ​​attack / malware

A confusing backdoor

A new phishing campaign has been spotted using tax-themed lures to deliver hidden backdoor payloads in attacks against Pakistan.

Cybersecurity company Securonix, which tracks activity under the name FLUX#CONSOLEsaid it most likely starts with a phishing link to an email or attachment, although it said it could not obtain the original email used to launch the attack.

“One of the most notable aspects of the campaign is how threat actors use Microsoft Common Console Document (MSC) files to deploy a bootloader and dual-purpose bootloader to deliver further malicious payloads,” security researchers Dan Yuzwick and Tim Peck said.

It should be noted that the abuse of specially crafted saved Management Console (MSC) files to execute malicious code has been codenamed GrimResource by Elastic Security Labs.

The starting point is a double-extension file (.pdf.msc) that masquerades as a PDF file (when the setting to display file extensions is disabled) and is designed to execute embedded JavaScript code when launched using the Microsoft Management Console (MMC). ).

Cyber ​​security

This code, in turn, is responsible for receiving and displaying the decoy file, as well as stealthily loading a DLL file (“DismCore.dll”) in the background. One such document used in the campaign is called “Tax Reductions, Rebates and Credits 2024” which is a legal document related to Pakistan Federal Board of Revenue (FBR).

“In addition to delivering the payload from an embedded and obfuscated string, the .MSC file is able to execute additional code by accessing a remote HTML file, which also achieves the same goal,” the researchers said, adding that persistence is established using a scheduled task.

The main payload is a backdoor capable of contacting a remote server and executing commands sent to it to steal data from compromised systems. Securonix said the attack was stopped 24 hours after the initial infection.

“From the highly obfuscated JavaScript used in the initial stages to the deeply hidden malware code in DLLs, the entire chain of attacks illustrates the complexity of detecting and analyzing modern malware,” the researchers said.

“Another notable aspect of this campaign is the use of MSC files as a potential evolution of the classic LNK file that has been popular with threat actors over the past few years. Like LNK files, they also allow malicious code to be executed during mashup. into legitimate Windows administrative workflows.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.