This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
As with most Fancy Bear affiliated malware, Cannon is distributed via spear-phishing campaigns with an attached Microsoft Word document. Once opened, the Word document will immediately attempt to retrieve a remote template containing a malicious macro. When the document is closed, the macro will install Cannon.
Cannon uses a complex system of email accounts to connect to a command and control server (C2), in an attempt to avoid detection. Once installed on a device, Cannon gathers system information and screenshots. If the infected system is of interest to the attacker, they will use Cannon to deliver other malware in a targeted attack.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 17 February 2020 1:00 pm