Skip to main content

Advanced Word Document Infection

Security researchers have dissected a recent malware campaign which uses malicious Microsoft Word documents with new techniques to avoid detection.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Security researchers have dissected a recent malware campaign which uses malicious Microsoft Word documents with new techniques to avoid detection.

Affected platforms

The following platforms are known to be affected:

Threat details

Microsoft Word files loaded with scripts that launch exploits using embedded files is far from a new tactic. However the new malware campaign differs in a number of ways - it contains new anti-detection mechanisms and it can swap the final payload depending upon the vulnerabilities present on the user's system.

The final exploit payload is not embedded within the document but obtained via a Command and Control (C2) infrastructure. A complicated process unwraps various layers including functions later used which are hidden within the C2 and encrypted. This prevents detection by anti-virus software and also assists with reconnaissance to determine the type of attacks.

The document itself is a Rich Text Format (RTF) document with a number of embedded objects found within. The first is an Object Linking and Embedding (OLE) object that holds an Adobe Flash object. The Flash object extracts a second Flash object embedded within itself which is encoded using two different compression algorithms.

The second Flash object identifies the URL of the C2 infrastructure, miropc[.]org, and sends an HTTP request to the “/nato” directory in that URL. System information of the user's device is collected by flash.system.Capabilities.serverString which is usually used by legitimate Flash files to obtain the capabilities of the installed Adobe Flash version. This information allows the attacker to make decisions about whether to continue the attack and what type of attack will be effective.

Further HTTP requests are sent to different C2 URL directories which vary for each attack. An exchange of encrypted files delivers the encrypted payload which is decrypted and executed to compromise the machine. In some cases the payload is swapped and instead delivers a substantial amount of junk data designed to hamper the activities of security researchers.


Remediation steps

Type Step
  • Documents with scripted content should be blocked from entering the estate where possible.
  • Ensure all end user software is kept up-to-date.
  • Ensure multilayer security approaches are used to increase the likelihood that an attack is detected and mitigated along with trend analysis to help identify periods of unusual activity that can be further investigated.

Last edited: 17 February 2020 11:25 am