Hacker Launching Malware via Wepaonized Version of PDF & Word Documents




Hacker Launching Malware via Wepaonized Version of PDF & Word Documents 

Cyber Criminals launching a new malware via weapon zed PDF & MS Word Version of New Zealand terror suspect’s manifesto.

Researchers noticed 8chan, an image board website composed of user-created boards contains several posts that link to a manifesto, allegedly authored by the terror suspect of New Zealand terror attack.

These Manifesto contain several version of PDF and Word Documents and these documents were circulated in the underground forums since the document has gone viral on the internet.

In this case, attackers taking advantage of this manifesto propaganda to distribute a Trojan version of the manifesto Titled ‘The Great Replacement’, The Weapon zed version of the manifesto resembles content from the original manifesto with several other future.

According to Blue Hexagon Research, “The metadata from the original manifesto states the author as the name of the alleged suspect who has been arrested in connection with the terror attack, whereas the author info in the weapon zed Trojan says it was created by the author ‘Maori’ (a name for the indigenous people of New Zealand). “

Weaponries PDF & MS Word Version
once users click the malformed PDF & MS word version, an obfuscated VBA script gets executed and download the next stage of payload.-‘Haka.exe’. The second stage of the payload is a PE file that is limited to overwriting the Master Boot Record (MBR) with a message displayed to force restart the system.

After the successful execution, the system gets restarted and displays the following massage.

Based on the attack scenario, there is no motivation behind this malware other than being disruptive. But this incident can be abused by other sophisticated malware by leveraging these weapon zed documents.


Sources by: cybernews001


Share this

Related Posts

Previous
Next Post »