Phishing Campaign Use CSV Text Files To Install Malware

Share post:

A malicious comma-separated values (CSV) file is now used to infect devices with the malware BazarBackdoor.

The malware BazarBackdoor was developed by the TrickBot group and gives attackers remote access to an internal file that can be used to spread laterally within a network.

A CSV is considered harmless because it is a simple text with no executable code. However, a Dynamic Data Exchange (DDE) feature in Microsoft Excel can be used to execute commands whose output is inputted into the open table, including CSV files.

The phishing campaign disguised as the Payment Remittance Advice provides links to remote websites that download a CSV file with names similar to ‘document-21966.csv.’

This text file contains a strange WMIC call in one of the columns of data called a DDE function. The DDE uses WMIC to create a new PowerShell process, which opens a remote URL, which contains another PowerShell command, which is then executed.

However, the process of installing the malware is not complete without users confirming the execution of the DDE function.

For more information read the original story in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways