Author

Topic: Microsoft Excel can be used to delivered LimeRAT and install cryptominer (Read 141 times)

legendary
Activity: 2576
Merit: 1655
Speaking of Excel, this one is a Covid-19 related them attacks, Phishing Attack Says You're Exposed to Coronavirus, Spreads Malware.

Email will tell that you need to print the attached spreadsheet.

Code:
EmergencyContact.xlsm

And when you open the attachment, it will asked you to "Enable Content" view to see the protected document. And once you enable, it will download a malware.

  • Search for and possibly steal cryptocurrency wallets.
  • Steals web browser cookies that could allow attackers to log in to sites with your account.
  • Gets a list of programs running on the computer.
  • Looks for open shares on the network with the net view /all /domain command.
  • Gets local IP address information configured on the computer.
legendary
Activity: 3080
Merit: 1353
According to the researcher from Mimecast:

Quote
LimeRAT Malware Exploited in the Wild
Recently, Mimecast threat intelligence researchers came across a campaign which used this Excel VelvetSweatshop encryption technique to deliver LimeRAT, a malicious remote access trojan.

In this specific attack, the cybercriminals also used a blend of other techniques in an attempt to fool anti-malware systems by encrypting the content of the spreadsheet hence hiding the exploit and payload.

Once LimeRAT has landed, the attacker has many capabilities at his or her fingertips, including delivering ransomware, a cryptominer, a keylogger, or creating a bot client.

Of course, given the general capability inherent with this Excel-based malware delivery technique, any type of malware is a good candidate for delivery, so Mimecast researchers expect to see it used in many more malicious phishing campaigns in the future. Mimecast Threat Center has alerted Microsoft to this campaign. 


Source

So be watch out of some Excel coming into your inbox that is password protected. Don't used the the default password "VelvetSweatshop" to try and unlock it, otherwise your machine are going to be compromise.
Jump to: