Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/19/2017
04:20 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Microsoft Office Docs New Vessel for Loki Malware

Loki malware, built to steal credentials, is distributed via Microsoft Excel and other Office applications rigged with malicious 'scriptlets' to evade detection.

A stealthy new attack distributes Loki malware in Microsoft Excel spreadsheets and other Office applications.

The attack, which was discovered by Lastline Labs, is tough to detect in its early stages. It bypasses traditional antivirus and is often dismissed as a false positive because it relies on malicious "scriptlets" that are added to Office files using external links.

Earlier this month, Lastline published findings on a malicious Excel file with the ability to download and execute malware. They saw no evidence of macros, shellcode, or DDE functionality, and it showed a low detection on Virustotal, which typically indicates it's either an unknown technique or a false positive.

Less than two weeks later, the malicious Excel scriptlet-laden spreadsheet garnered 12 detections on Virustotal across 60 AV tools, a sign it went from false positive to potential infection.

"One of the things [researchers] saw was a spike in Microsoft Office documents, Excel spreadsheets that were calling back and downloading a new payload without the use of any sort of macros or shell code," explains Andy Norton, director of intelligence at Lastline. "We found criminal groups were embedding URLs in scriptlets inside Office documents and using that as a method of evading detection."

When victims open a malicious Excel file they are prompted to update the workbook's external links, an Office feature that lets authors reference external resources rather than embedding them directly. This keeps files small and easier to update. Unfortunately, external links can reference malicious scriptlets and deliver payloads without leveraging traditional delivery methods.

In this case, Excel scriptlets are delivering Loki, a type of malware known for exfiltrating usernames and passwords. The password stealer is designed to take credentials from software including email clients, browsers, FTP clients, and file management clients.

"What we're witnessing is an evolution in how bad guys are going to put malicious payloads into organizations," says Norton. "We've seen that a lot of the samples of what we've collected are not known to Virustotal."

The malicious files arrive via standard email. Once credentials have been lifted, Loki displays to attackers which websites are vulnerable to identity theft. This could include social media sites, payment portals, or bitcoin wallets.

This attack exploist CVE-2017-0199, a Microsoft Office/WordPad RCE security vulnerability with Windows API, which was patched in April 2017 and updated in September. The flaw exists in the way that Office and WordPad parse specially crafted files. Exploitation requires a victim to open or preview a malicious file. An attacker could install programs, view or edit data, or create accounts with full user rights. Norton says while attackers could move across the internal environment, the primary goal here is to steal credentials from the target victim's system.

'Double Whammy'

Lastline calls this vector a "double whammy" for security response teams because it aims to both evade detection and correct remediation. The attack vector's low detection rate leads to the assumption it's a false positive. However, even if businesses discover the threat is Loki, most don't correctly address the problem. Attackers know this.

The guidance around remediation for generic Trojans is to "reinstall a backup" or "reimage and start fresh," Norton explains. "Now if you do that, Loki's won. There's nothing in remediation advice about changing all the passwords on the systems."

"It's important to get clear information about the capabilities and capacity of the threat," he continues. "If you don't, you're making yourselves vulnerable to a secondary stage of attack where credentials are used to get back into the environment."

Norton says victims can tell they've been hit if they understand the behaviors of the attack, something he says is "becoming increasingly vital." Behavioral analysis platforms can help here, he notes. For those who have been hit, he advises reimaging and resetting all passwords.

Lastline's work is a "live research project," he says, so expect more updates. On Friday, the researchers discovered payload distribution was changed to a website that had been linked to an Iranian botnet attack in May 2017. About five different threat groups have been using this particular payload, Norton notes, and they likely come from all over the globe.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
aqibseo
50%
50%
aqibseo,
User Rank: Apprentice
6/29/2018 | 8:15:49 PM
that is much easy why you writing artical on it
you missed some of points 
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
IoT Vulnerability Disclosure Platform Launched
Dark Reading Staff 10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26649
PUBLISHED: 2020-10-22
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
CVE-2020-26650
PUBLISHED: 2020-10-22
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
CVE-2020-27533
PUBLISHED: 2020-10-22
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
CVE-2020-24033
PUBLISHED: 2020-10-22
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escala...
CVE-2020-27560
PUBLISHED: 2020-10-22
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.