Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Ethereum Takes Hit, Why ETH Could Plunge Below $2,700 bitcoin news
  • New American Express Credit Card Lets Shoppers Earn Crypto Rewards Tradable Across 100+ Cryptocurrencies – Featured Bitcoin News bitcoin news
  • Celsius Network’s Token CEL Drops 58% After Bankruptcy Filing, So-Called ‘Short Squeeze’ Falters – Markets and Prices Bitcoin News bitcoin news
  • Bitcoin Funding Rate Turns Highly Positive, Long Squeeze In The Making? bitcoin news
  • Russia Developing Sandbox for Cross-border Crypto Payments – Bitcoin News bitcoin news
  • Bitcoin Price Turns Red, Why BTC Could Extend Losses bitcoin news
  • Landfill Gas Mitigation Firm Vespene Energy Secures $4.3M to Bolster Gas-to-Bitcoin Solutions – Bitcoin News bitcoin news
  • GRN (G) Is Now Available for Trading on LBank Exchange – Press release Bitcoin News bitcoin news

Hackers Exploiting Follina Bug to Deploy Rozena Backdoor

Posted on July 9, 2022 By root


Rozena Backdoor

A newly observed phishing campaign is leveraging the recently disclosed Follina security vulnerability to distribute a previously undocumented backdoor on Windows systems.

“Rozena is a backdoor malware that is capable of injecting a remote shell connection back to the attacker’s machine,” Fortinet FortiGuard Labs researcher Cara Lin said in a report this week.

Tracked as CVE-2022-30190, the now-patched Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability has come under heavy exploitation in recent weeks ever since it came to light in late May 2022.

The starting point for the latest attack chain observed by Fortinet is a weaponized Office document that, when opened, connects to a Discord CDN URL to retrieve an HTML file (“index.htm“) that, in turn, invokes the diagnostic utility using a PowerShell command to download next-stage payloads from the same CDN attachment space.

This includes the Rozena implant (“Word.exe”) and a batch file (“cd.bat”) that’s designed to terminate MSDT processes, establish the backdoor’s persistence by means of Windows Registry modification, and download a harmless Word document as a decoy.

The malware’s core function is to inject shellcode that launches a reverse shell to the attacker’s host (“microsofto.duckdns[.]org”), ultimately allowing the attacker to take control of the system required to monitor and capture information, while also maintaining a backdoor to the compromised system.

Rozena Backdoor

The exploitation of the Follina flaw to distribute malware through malicious Word documents comes as social engineering attacks relying on Microsoft Excel, Windows shortcut (LNK), and ISO image files as droppers to deploy malware such as Emotet, QBot, IcedID, and Bumblebee to a victim’s device.

The droppers are said to be distributed through emails that contain directly the dropper or a password-protected ZIP as an attachment, an HTML file that extracts the dropper when opened, or a link to download the dropper in the body of the email.

CyberSecurity

While attacks spotted in early April prominently featured Excel files with XLM macros, Microsoft’s decision to block macros by default around the same time is said to have forced the threat actors to pivot to alternative methods like HTML smuggling as well as .LNK and .ISO files.

Rozena Backdoor

Last month, Cyble disclosed details of a malware tool called Quantum that’s being sold on underground forums so as to equip cybercriminal actors with capabilities to build malicious .LNK and .ISO files.

It’s worth noting that macros have been a tried-and-tested attack vector for adversaries looking to drop ransomware and other malware on Windows systems, whether it be through phishing emails or other means.

Microsoft has since temporarily paused its plans to disable Office macros in files downloaded from the internet, with the company telling The Hacker News that it’s taking the time to make “additional changes to enhance usability.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: South African Firm Launches ‘Crypto Water Token’ — Receives Investment of $150M – Bitcoin News
Next Post: Can Cardano (ADA) Reach $4 To Surpass Ethereum Market Cap?

Related Posts

  • New Android Banking Trojan ‘Revive’ Targeting Users of Spanish Financial Services cyber security news
  • NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages cyber security news
  • YODA Tool Found ~47,000 Malicious WordPress Plugins Installed in Over 24,000 Sites cyber security news
  • The New Weak Link in SaaS Security: Devices cyber security news
  • GitHub Dependabot Now Alerts Developers On Vulnerable GitHub Actions cyber security news
  • Over 200 Apps on Play Store Caught Hacking Androids with Password Stealer cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • India Freezes Peter Thiel-Backed Vauld’s Crypto and Bank Assets Worth $46 Million – Regulation Bitcoin News
  • Ethereum Price Broke Past $1,800 Despite Higher Demand At Lower Levels
  • Philippines Will Stop Accepting Crypto License Applications for 3 Years, Regulator Says – Regulation Bitcoin News
  • GAIMIN’s Early Access Event Opens Its Platform and Monetization App to Gamers – Press release Bitcoin News
  • Cardano Price Sits Pretty At $0.5, Why A Breakout Is On The Horizon

Recent Comments

No comments to show.
  • Ethereum Eyes Fresh Surge, Why ETH Could Surpass $1,700 bitcoin news
  • Celsius Stories Littered With ‘People Familiar With the Matter’ Sources, Report Claims Lender Struggles With Arguments Over Bankruptcy – Bitcoin News bitcoin news
  • Funko Partners With Entertainment Giant Paramount to Drop Avatar Legends NFTs – Blockchain Bitcoin News bitcoin news
  • FBI Arrests 2 Men Planning ‘Violent’ Robbery of Bitcoin Worth Millions of Dollars — They Face 20 Years in Prison – Regulation Bitcoin News bitcoin news
  • Senator Indira Kempis Proposes Bill to Make Bitcoin Legal Tender in Mexico – Regulation Bitcoin News bitcoin news
  • UST Rebounds From $0.66 per Coin to $0.93, Crypto Community Assesses Stablecoin’s Damaged Reputation – Bitcoin News bitcoin news
  • Elon Musk, Mark Cuban Discuss Using Dogecoin to Solve Twitter Spam Problem – Altcoins Bitcoin News bitcoin news
  • Chinese Hackers Targeting Russian Military Personnel with Updated PlugX Malware cyber security news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme