SpicyOmelette Remote Access Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
SpicyOmelette is utilised during the initial stages of an attack to gain a backdoor in the target network. It has been distributed via spear phishing campaigns that use emails with a legal theme.
The phishing emails contain a link that appears to lead to a PDF document, but this actually leads to the SpicyOmelette JavaScript file. This file is digitally signed using a valid certificate issued to a front company by a valid and trusted certificate authority.
When executed, SpicyOmelette installs a Dynamic-link Library (DLL) payload and creates a decoy document to display to the user. The DLL payload drops a valid Microsoft utility onto the system with a randomly named JavaScript file and two randomly named text files.
SpicyOmelette allows the APT to collect system information, check for the presence of anti-malware tools, execute arbitrary JavaScript code and install additional malware onto the affected device.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:55 pm