The Microsoft Security Intelligence team has detailed how the campaign is being used to remotely access systems with malicious Excel files.
Through a series of tweets, the Microsoft Security Intelligence team has detailed the ongoing phishing attacks. The team says that the campaign delivers the NetSupport Manager using emails with attachments containing malicious Excel 4.0 macros.
As per the details provided by the Microsoft team, the attack begins with emails that pretend to come from Johns Hopkins Center and show details about the active COVID-19 cases in the US. However, in reality, the emails include Excel files that once open, show a graphical representation of the coronavirus data. However, the files also include malicious Excel 4.0 macros that will prompt users to “Enable Content”. This begins the download and installation process of the NetSupport Manager client from a remote site.
“For several months now, we've been seeing a steady increase in the use of malicious Excel 4.0 macros in malware campaigns. In April, these Excel 4.0 campaigns jumped on the bandwagon and started using COVID-19 themed lures,” the team notes in one of its tweets.
Once the remote access tool is installed on a victim's system, the attackers can access and run commands remotely.
In a particular case, the Microsoft team has noticed that the NetSupport Manager was used to drop multiple components, including some executable files and establish connectivity with a C2 server to enable further commands from the attackers.
Pay attention to what you're downloading from emails
Users are recommended to avoid paying attention to random emails and verify email addresses from where they're receiving new emails before downloading the included attachments. Also, it is suggested to immediately change passwords if you find any odd behaviour on your system.
Microsoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacksMicrosoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacksMicrosoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacksMicrosoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacksMicrosoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacksMicrosoft Security Intelligence,Microsoft,COVID 19 phishing attacks,coronavirus,COVID 19,phishing attacks

