Endpoint

2/2/2016
08:00 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Macro Malware Resurgence Highlighted By Kasidet Outbreak

Also known as Neutrino, this piece of malware is another case of Office macro malaise.

The Neutrino bot is getting a new boost of rejuvenation from a retro form of distribution that's been making a huge comeback lately. According to research last week out from Zscaler, Neutrino--also known as Kasidet--has spiked again in the wild with the help of malicious Microsoft Office macros. This latest example of VBA-related malware is another piece of evidence that a once forgotten class of malware has roared back to life in the last 18 months.

The delivery of Kasidet backdoors is the continuation of a months-long series of campaigns to drop the Dridex banking malware on victim computers using malicious macros, Zscaler reseachers say.

"Over the past two weeks we are seeing these malicious VBA macros leveraged to drop Kasidet backdoor in addition to Dridex on the infected systems," Zscaler's researchers wrote. "These malicious Office documents are being spread as an attachment using spear phishing emails."

The variant of Kasidet identified in this latest campaign features two main information-stealing features. The first is through browser hooking. And the second is through the point-of-sale (POS) system memory scraping functionality Kasidet is starting to increasingly employ. Once known primarily for its distributed denial-of-service (DDoS) arsenal, its POS targeting features began popping up in earnest last spring.

"Upgrading old malware to include PoS RAM-scraping capabilities is a new technique in the threat landscape, but it’s not surprising given how lucrative stolen payment card data is. It shows that more and more cybercriminals are putting two and two together to make more money," wrote TrendMicro researchers  in an explanation last fall of the phenomenon.

Zscaler researchers say that the inclusion of Kasidet in an ongoing push for Dridex shows how much cyber crooks share underlying infrastructure and delivery mechanisms. As such, infosecurity professionals should expect to see more macro malware in 2016.

According to the most recent McAfee Labs Threat Report Office macro malware has reached a crescendo over the last 18 months. Barely making a dent  in 2013, it started coming back gradually in 2014 until it spiked at the end of that year. Since then, criminals have been on a tear taking advantage of macro vulnerabilities. At the end of third quarter in 2015, year over year growth in macro threats tripled. And McAfee says it has reached its highest level since 2009. 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-2486
PUBLISHED: 2018-12-11
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2492
PUBLISHED: 2018-12-11
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.
CVE-2018-2494
PUBLISHED: 2018-12-11
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.
CVE-2018-2497
PUBLISHED: 2018-12-11
The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.
CVE-2018-2500
PUBLISHED: 2018-12-11
Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.