American toy company Mattel reports that it suffered from ransomware attack, that affected some business…
The attack starts with a simple phishing email allegedly related to the GDPR. The email contains an attached Word document containing a malicious macro. When this document is opened, a malicious macro extracts an image of a fox from the animated series Dora the Traveler.
The image above is not as innocuous as it might first appear, as it uses shorthand to hide a PowerShell script. This script will download and install the Windows Chocolatey package manager, which will then be used to install Python and the PIP package installer.
Chocolatey is also used to avoid detection by security software, as it is often used in corporate environments and is often on the allowed list.
As a result, a second steganographic image is loaded into the victim’s system to download the Serpent backdoor, which is a malware written in Python (therefore, previously installed packages were required in the previous steps).
Attack scheme
Serpent, in turn, will contact the hackers’ control server to receive commands to be executed on the infected device. According to analysts, the backdoor is capable of executing any command of its operators, allowing it to download additional malware, open reverse shells, and gain full access to the device.
Let me remind you that we also talked about the fact that Hacked Oxford server was used for phishing attacks on Office 365, and also that APWG Notes Three-Year Phishing Record.
1.99 is a site that tries to trick you into clik to its browser notifications…
Dolophin.com is a site that tries to force you into clik to its browser notifications…
Maxfirewall.co.in is a site that tries to force you into subscribing to its browser notifications…
Opennetworklink.co.in is a domain that tries to force you into clik to its browser notifications…
Nopixelads.top is a site that tries to force you into subscribing to its browser notifications…
Unhesiss.shop is a domain that tries to trick you into clik to its browser notifications…