New JavaScript Malware Dubbed KopiLuwak
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The macro used in this campaign has modifications compared to previous versions. There is an XOR encryption routine that is used to decode the initial JavaScript and uses a marker string to find the embedded payload in the document. The malware is able to maintain persistence across reboots by adding an entry into the registry. Multiple layers of JavaScript have been implemented within the code to specifically avoid detection.
The C2 servers that are used are legitimate websites that have been compromised and used for communications. Each of the infected hosts is assigned a custom User Agent (UA) String that is used to make POST requests to the C2 server. The UA String consists of the system name and the user name which are then passed through a routine that produces a unique ID consisting of 16 digits, with a string appended to the end.
Remediation steps
Last edited: 17 February 2020 11:36 am