[ << ALL_FEED ]

Friday newsletter

More in General

Friday Newsletter 🐽

Imagine: you’re an employee of a Russian organization, and on Friday someone named Nadezhda Arturovna 😌 sends you an email (screenshot 1) asking you to take a survey. As always, a federal enterprise employee is asking for everything and as quickly as possible. Your actions? 🤔

If you believe the fake employee and try to take the survey, inside the archive you’ll find a file with the same name, Опросный_лист_ЦРП_ВПК_Предзаполненны.xll (you noticed the typo too, right?). It’s a DLL — a special Microsoft Excel module. When the xll file is opened, a malicious payload %LOCALAPPDATA%\\Comms\\mspm.exe is dropped and executed, while you, suspecting nothing, will only see a decoy spreadsheet %USERPROFILE%\\Documents\\Tablica1.xls (screenshot 2) 😶

But we sincerely hope that, despite it being Friday, you’re vigilant 👓. After all, the payload itself is an AI-generated backdoor WarpPlugin, also known as EchoGather — a known GOFFEE tool. Its main capabilities include:

🐾 executing CMD commands to control and explore the victim’s computer
🐾 exfiltrating files from that system
🐾 uploading files sent by GOFFEE to that system

We’ve been observing this kind of activity since the end of last year 😏. GOFFEE eagerly uses AI agents, constantly generating new decoy files and variations of the WarpPlugin backdoor. The threat actors also don’t skip constantly generating new names for C2 addresses.

IoCs

9c189eb72315960a6bc10d25dc8f8808f9ed13088951bae37ca0d7502fec8e10
1b6dd18db3da8b9df1c3ca99a2de0a0296ce7c5f92c2f6a6a8831d0e4f61aed1
b02c4d355a1c8f3209f62221b2bafcfefa3ab1444461a209fdcd75fa04f4fb1e
f75b3e37c9683d4862e71ef204fd4128169168ce22e2722618b9aed69bf6add0
https://ntp.report/api/v4/projects/report/nowCode language: YAML (yaml)


#Malware #TI #APT
@ptescalator

More from ti_author

More from ti_author

More in General