LokiBot Malware Targets Windows Users in Office Document Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-40444 | Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444) CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021. Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file. | 8.8 | 97% | KEV ransomware PoC ×2 |
| masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure) | |
| CVE-2022-30190 | MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina) CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28. Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly. | 7.8 | 99% | KEV ransomware PoC |
| mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base) |
Full article341 words · extracted from infosecurity-magazine.com · click to collapse
Windows users have been targeted again by the sophisticated malware known as LokiBot, which is spreading through malicious Office documents.
According to a new advisory by Fortinet security researcher Cara Lin, attackers are leveraging known vulnerabilities, such as CVE-2021-40444 and CVE-2022-30190, to embed malicious macros within Microsoft Office documents.
Once executed, these macros drop the LokiBot malware onto victims’ systems, allowing the attackers to control and collect sensitive information.
LokiBot, a notorious Trojan active since 2015, specializes in stealing sensitive information from infected machines, primarily targeting Windows systems.
Read more on LokiBot infections: Lokibot, AgentTesla Grow in January 2023's Most Wanted Malware List
FortiGuard Labs conducted an in-depth analysis of the identified documents, exploring the payload they delivered and highlighting the behavioral patterns exhibited by LokiBot.
The investigation revealed that the malicious documents employed various techniques, including the use of external links and VBA scripts, to initiate the attack chain.
The LokiBot malware, once deployed, used evasion techniques to avoid detection and executed a series of malicious activities to gather sensitive data from compromised systems.
“It’s serious in three ways,” said John Gallagher, vice president of Viakoo Labs at Viakoo, referring to the new attack. “It’s new packaging for LokiBot and may not be detected easily, it is effective in covering its tracks and obfuscating its process, and it can lead to significant personal and business data being exfiltrated.”
To protect against this threat, users are advised to exercise caution when dealing with Office documents or unknown files, particularly those containing external links.
“Fortunately, Microsoft is on top of the problem from a resolution and workaround perspective, so it’s imperative that we remind everyone to keep their endpoint protection products current,” commented Andrew Barratt, vice president at Coalfire.
“This also shows the value of email filtering solutions that can actively scan an attachment before it lands in someone’s inbox.”
The Fortinet advisory comes days after Barracuda Networks published a report suggesting a relatively small group of scammers, numbering fewer than 100 individuals, is responsible for global email extortion.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/lokibot-malware-targets-windows/