Infosecurity Magazine reports that increasingly covert cyberattacks are being facilitated by the growing use of new living-off-the-land techniques.
Malicious Compiled HTML Help files purporting to be project documentation attachments have been distributed as part of a campaign that sought to facilitate multi-stage compromise, with various Windows LOTL binaries leveraged by the embedded script that eventually resulted in the deployment of the XWorm payload within the MSBuild process, an HP Wolf analysis revealed.
Another attack campaign harnessed minuscule scalable vector graphics files, which opened a spoofed Adobe Acrobat Reader interface to lure victims into downloading a ZIP archive with malware. Threat actors have also leveraged phishing emails with IMG archives to facilitate the distribution of the Lumma Stealer malware without triggering security systems.
"We're seeing more chaining of living-off-the-land tools and use of less obvious file types, such as images, to evade detection," said HP Security Lab Principal Threat Researcher Alex Holland.
Malicious Compiled HTML Help files purporting to be project documentation attachments have been distributed as part of a campaign that sought to facilitate multi-stage compromise, with various Windows LOTL binaries leveraged by the embedded script that eventually resulted in the deployment of the XWorm payload within the MSBuild process, an HP Wolf analysis revealed.
Another attack campaign harnessed minuscule scalable vector graphics files, which opened a spoofed Adobe Acrobat Reader interface to lure victims into downloading a ZIP archive with malware. Threat actors have also leveraged phishing emails with IMG archives to facilitate the distribution of the Lumma Stealer malware without triggering security systems.
"We're seeing more chaining of living-off-the-land tools and use of less obvious file types, such as images, to evade detection," said HP Security Lab Principal Threat Researcher Alex Holland.
