https://bit.ly/3R6hgF2 - π AhnLab Security Emergency Response Center (ASEC) reports that malware previously dispersed in CHM format is now being circulated in LNK format. The malware pulls scripts from specific URLs using the mshta process, subsequently receiving commands from the threat actorβs server for additional malicious actions. #CyberSecurity #MalwareAlert π The malware has been found on regular websites, hidden within compressed files. One notable LNK file named 'https://bit.ly/487ONVA' has been uploaded. This file, similar to other known threats, contains both standard Excel data and malicious scripts. Upon execution, it opens a seemingly harmless Excel file while also running a hidden malicious script. #DigitalThreat #MalwareDetections π‘ This malware mimics a Korean public institution's document. When activated, the malware copies itself into system folders and registers keys in the system's registry to ensure its continued execution. Detailed analysis reveals the malware communicates with certain URLs, receiving and processing commands from its controlling entity. #InfoSec #DigitalForensics π A breakdown of the malware's actions reveals its capability to gather PC and drive information, collect clipboard content, manage services and processes, execute commands, and interact with files and registries. New script modifications suggest the attacker's constant adaptation and potential for more varied malicious activities. #CyberAttack #ThreatAnalysis πΌ Alongside the aforementioned LNK file, other compressed files were discovered, housing the previously detected malicious CHM file. This CHM malware, similar to the LNK, leverages mshta to fetch and execute scripts from designated URLs. π« With a rise in malware distribution via CHM and LNK files, ASEC urges users to be vigilant. Especially concerning are LNK files over 10MB from unknown sources, which users are strongly advised against executing.
Loading...
















