The number of scams around the globe are suddenly on a rise as the world continues to deal with coronavirus pandemic. Seqrite, a specialist provider of endpoint security, network security, enterprise mobility management, and data protection solutions, has detected a new MalSpam (malicious spam) campaign, targeting manufacturing and export sectors in India.

COMMERCIAL BREAK
SCROLL TO CONTINUE READING

The researchers of Seqrite spotted that malware actors are leveraging multiple sophisticated techniques in this campaign to bypass traditional defence mechanisms. However, Seqrite is successfully detecting and blocking any such attempts using its patented Signatureless and Signature-based detection technology.

According to Seqrite, some of the common Remote-Access-Tools used by attackers are Agent Tesla, Remcos RAT and NanoCore RAT. 

How do these attacks happen?

The fraudsters send a phishing email to a genuine user which contains MS Office PowerPoint files with a malicious Visual Basic for Applications (VBA) macro. Cyber Attackers use VBA programming in Microsoft Office macros as a medium to spread viruses, worms, and other forms of malware on a computer system.

WATCH Zee Business TV LIVE Streaming Online

Post execution, the malware takes advantage of pre-existing legitimate software to download malicious payload from Pastebin and continues to spread the infection.

These types of hacks use LoLBins or living-off-the-land binaries which are built-in tools on operating systems, used for legitimate purposes. Attackers abuse these tools for malicious objectives as security products usually whitelist them. 

How to stay safe?

The researchers suggest that timely detection and blocking of such attack campaigns is essential for maintaining the integrity and trust in the businesses. Seqrite recommends users to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Businesses should consider disabling macros, keep their Operating Systems updated and have a full-fledged security solution installed on all the devices.