By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks
Tech News

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks

By Viral Trending Content 3 Min Read
Share
SHARE

Dec 17, 2024Ravie LakshmananCyber Attack / Malware

Obfuscated Backdoor

A new phishing campaign has been observed employing tax-themed lures to deliver a stealthy backdoor payload as part of attacks targeting Pakistan.

Cybersecurity company Securonix, which is tracking the activity under the name FLUX#CONSOLE, said it likely starts with a phishing email link or attachment, although it said it couldn’t obtain the original email used to launch the attack.

“One of the more notable aspects of the campaign is how the threat actors leverage MSC (Microsoft Common Console Document) files to deploy a dual-purpose loader and dropper to deliver further malicious payloads,” security researchers Den Iuzvyk and Tim Peck said.

It’s worth noting that the abuse of specially crafted management saved console (MSC) files to execute malicious code has been codenamed GrimResource by Elastic Security Labs.

The starting point is a file with double extensions (.pdf.msc) that masquerades as a PDF file (if the setting to display file extensions is disabled) and is designed to execute an embedded JavaScript code when launched using the Microsoft Management Console (MMC).

Cybersecurity

This code, in turn, is responsible for retrieving and displaying a decoy file, while also covertly loading a DLL file (“DismCore.dll”) in the background. One such document used in the campaign is named “Tax Reductions, Rebates and Credits 2024,” which is a legitimate document associated with Pakistan’s Federal Board of Revenue (FBR).

“In addition to delivering the payload from an embedded and obfuscated string, the .MSC file is able to execute additional code by reaching out to a remote HTML file which also accomplishes the same goal,” the researchers said, adding that persistence is established using scheduled tasks.

The main payload is a backdoor capable of setting up contact with a remote server and executing commands sent by it to exfiltrate data from compromised systems. Securonix said the attack was disrupted 24 hours after initial infection.

“From the highly obfuscated JavaScript used in the initial stages to the deeply concealed malware code within the DLL, the entire attack chain exemplifies the complexities of detecting and analyzing contemporary malicious code,” the researchers said.

“Another notable aspect of this campaign is the exploitation of MSC files as a potential evolution of the classic LNK file which has been popular with threat actors over the past few years. Like LNK files, they also allow for the execution of malicious code while blending into legitimate Windows administrative workflows.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Galway-based AI start-up Octostar raises €6.1m

How the Vision Pro Rollout Inflamed Tensions at Apple

Starfield Animated Short Showcases the Terran Armada’s Brutal Efficiency (and Delta’s Origins)

Donut Labs Solid-State Battery Tests : VTT Data & Doubts

A Single Strike Won’t Shut Off the Gulf’s Desalination System

TAGGED: Cyber Security, Cybersecurity, Internet, JavaScript, Malware, Microsoft, MSC, phishing attack, Securonix
Share This Article
Facebook Twitter Copy Link
Previous Article Dungeons and Dragons: Dark Alliance is Getting Delisted on December 24th, Servers Shutting Down
Next Article Colorado voters undecided in early poll of governor’s race for 2026 Democratic primary
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Galway-based AI start-up Octostar raises €6.1m
Tech News
How the Vision Pro Rollout Inflamed Tensions at Apple
Tech News
Chelsea attempt to clean up nightmare international break with Port Vale smashing – opinion
Sports
CEOs are lining up behind the $1,000 Trump Accounts for babies
Business
Bitcoin ETF inflows hit $471M, highest since late February
Crypto
Crypto Leaders ‘Hopeful’ On Latest Stablecoin Yield Language – Was A Solution Reached?
Crypto
Starfield Animated Short Showcases the Terran Armada’s Brutal Efficiency (and Delta’s Origins)
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?