Locky updated to exploit Office DDE feature and spread ransomware
A legitimate feature in Microsoft Office that allows Word to load data from other documents is being exploited to push a new variant of the Locky ransomware. Victims are reportedly targeted with malspam messages via the infamous Necurs botnet.
Under the subject line “Emailed Invoice” followed by a string of random numbers, the malspam attack leverages Microsoft Dynamic Data Exchange (DDE). Distributed with the aid of the Necurs botnet, the exploit makes Microsoft Word display dialog messages that some users might dismiss reflexively, even though the dialogs contain security warnings.
Unbeknown to them, the succession of clicks ultimately downloads and runs the Locky ransomware, locking down the victims” hard drives and demanding 0.25 Bitcoin ($1,474 at today”s trading) in ransom money for the decryption keys.
Some reports claim that new version of Locky also exploits SMB flaws in non-patched computers on a network to spread to additional victims, in what would be described as wormable behavior similar to the WannaCry pathogen back in May. However, it isn’t yet clear if this is indeed the case.
The attack uses several elements to try and hide from antivirus software:
- It exploits what is essentially intended functionality (Microsoft itself calls DDE a feature, not a bug), so as the user clicks through the security warnings, it may already be too late. As infosec expert Vess (VessOnSecurity) puts it, “Works as intended, you do get a warning. Nothing to patch.”
- The attachment appears as a benign 7zip attachment, making it difficult for antimalware solutions to discriminate against it.
- It uses an encrypted txt file that gets converted to a working Locky file, again, after the fact.
- If email spoofing is employed, the infected file can appear to come from a known sender, further increasing the possibility of fooling the user.
The illustration above depicts â€“ in the simplest form â€“ how the attack unfolds, courtesy of Brad Duncan (on duty at ICS at the time of discovery).
The updated Locky ransomware has been circulating for two months, but no major attacks have so far been recorded.
Users should follow basic safety rules and avoid downloading email attachments they are not expecting.
Bitdefender security solutions protect against this new ransomware threat.
Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US
July 16, 2021
How to protect yourself against cyberstalking
July 06, 2021
The Top Five Security Risks Smartphone Users Face Today
July 02, 2021
Phishing Alert: Scammers Use Fake SharePoint and DocuSign Messages to Steal Users’ Login Credentials
July 02, 2021
Your Doxxing Dossier Will Keep Growing Thicker Until You See the Danger
June 30, 2021
Mobile security threats: reality or myth?
June 13, 2021
FOLLOW US ON
You might also like
July 23, 2021
July 22, 2021
July 20, 2021