• Home
  • Resources and Tips
    • Digital Resources
    • Physical Resources
    • Hints and Tips
  • Education
  • IT
  • Learning in the future
  • Schools
  • Students
  • Tech in education
What's hot

How to Digitize Historical School Videos

June 3, 2023

Six student loan tips for June 2023

June 3, 2023

Benson Public Schools considering Braves mascot due to new legislation – West Central Tribune

June 3, 2023

The future of entrepreneurship; why starting early is key – The Financial Express

June 3, 2023
Facebook Twitter Instagram
  • Home
  • Contact us
  • Privacy policy
  • Terms & Conditions
Facebook Twitter Instagram
Teaching Resources Pro
  • Home
  • Resources and Tips
    • Digital Resources
    • Physical Resources
    • Hints and Tips
  • Education

    Parent Empowerment Pop-Ups: Partnering with Parents for Perspective

    June 1, 2023

    Florida School Library moves Amanda Gorman’s inauguration poem after complaint

    May 30, 2023

    Can you guess these 10 words from the Scripps Spelling Bee?

    May 28, 2023

    Essay on “Every Brain Needs Music” and “Hi Ren”

    May 26, 2023

    Tips for reducing costs when implementing customer training software

    May 22, 2023
  • IT

    Discover the process flow of diversity in cyber

    June 3, 2023

    Bringing observability to the modern data stack

    June 1, 2023

    How do you find the user pain points that help the mobile app succeed?

    May 30, 2023

    How to Join a Node to a Docker Swarm

    May 28, 2023

    Five key steps when there is a risk of a fraud investigation

    May 26, 2023
  • Learning in the future

    The future of entrepreneurship; why starting early is key – The Financial Express

    June 3, 2023

    Early childhood: how to bring more nature to kindergarten – The Hechinger report

    June 1, 2023

    Q&A with Learning Analytics Graduate Anjali Ann Yadav – UW-Madison

    May 30, 2023

    Assad’s normalization leaves Syrians in Rukban’s camp fearful of the future – Al Jazeera

    May 28, 2023

    Montgomery middle schoolers ‘invent the future’ in unique STEM… – The Washington Post

    May 26, 2023
  • Schools

    Benson Public Schools considering Braves mascot due to new legislation – West Central Tribune

    June 3, 2023

    Texas Legislature’s Response to Uvalde: Armed Campus Security – Reuters

    June 1, 2023

    Hawkins County Schools Receive Propane School Bus Grant – Reuters

    May 30, 2023

    Ohio teacher shortage: As schools review vacancies, teachers fill gaps – cleveland.com

    May 28, 2023

    Reed City Public School students receive surprise gift ahead of summer break – Reuters

    May 26, 2023
  • Students

    Six student loan tips for June 2023

    June 3, 2023

    How to get a summer job as a student

    June 1, 2023

    College Move-in Day Tips – What NOT to do

    May 30, 2023

    Taking care of yourself during and after exam season – Student Blog

    May 28, 2023

    Fulfill my mission to attend conferences – SJSU

    May 26, 2023
  • Tech in education

    How to Digitize Historical School Videos

    June 3, 2023

    BookNook Names Education Veteran Jared Harless Chief Product Officer

    June 1, 2023

    What is Pocketalk? The translation tool explained

    May 28, 2023

    Improving English learning with technology in the classroom

    May 26, 2023

    Ten Ways to Use Adobe Express at School

    May 24, 2023
Teaching Resources Pro
Home»IT»Images of James Webb used to spread malware
IT

Images of James Webb used to spread malware

September 2, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Cybercriminals are exploiting some of the stunning new images captured by Nasa James Webb Space Telescope to indiscriminately spread malware to their targets, according to intelligence shared by the cloud security analytics specialist’s threat research team Securonix.

In a new report, Securonix analysts D Iuzvyk, T Peck and O Kolesnikov said they found a unique sample of a persistent campaign based on Golang, which they track as Go#Webfuscator.

As previously explored by Computer Weeklymalware based on Golang or Go is increasingly popular among cybercriminals, particularly because their binaries are harder to analyze and reverse engineer than C++ or C#, and because the language is more flexible in terms of cross-platform support , meaning they can target multiple systems at once without needing to be manipulated. Advanced Persistent Threat (APT) groups such as panda mustang are fans of it for these reasons.

Go#Webfuscator itself spreads via phishing emails containing a Microsoft Office attachment that contains, hidden in its metadata, an external reference that retrieves a malicious template file containing a Visual Basic script to initiate the first step of code execution, if the victim is unfortunate enough to enable macros.

After deobfuscating the Visual Basic code, the Securonix team discovered that it was running a command to download a .jpg image file and using the certutil.exe command line program to decode it into a binary and then run it.

The .jpg in question is the now famous Webb’s first deep field image, taken by the James Webb Space Telescope, which shows galaxy cluster SMACS 0723 in extraordinary detail, including some of the faintest and most distant objects ever observed in the infrared spectrum.

In this case, however, it contains malicious Base64 code disguised as an embedded certificate which, as of the date of Securonix’s disclosure, has not been detected by any anti-virus software. Once decrypted, this in turn is saved in an embedded Windows executable file, the Golang binary, i.e. the malware itself.

Go#Webfuscator is a Remote Access Trojan, or RAT, that recalls its command-and-control (C2) infrastructure and is used to establish an encrypted channel for control of the victim’s system, or to deliver payloads secondary useful to exfiltrate sensitive data, which could include passwords, account details and financial information, making its victims vulnerable to fraud or identity theft later on.

“Overall, the TTPs [tactics, techniques and procedures] seen with Go#Webfuscator throughout the attack chain are quite interesting. Using a legitimate image to create a Golang binary with certutil is not very common in our experience or typical and something we are monitoring closely,” the team wrote in its disclosure.

“Consumers should beware of unsolicited emails that use the James Webb Space Telescope as the subject and should avoid any Microsoft Office attachments containing a .jpg image, as this is used to automatically deliver the malicious payload”

Ray Walsh, ProPrivacy

“It is clear that the original author of the binary designed the payload with both trivial counter-crime and anti-EDR [endpoint detection and response] detection methodologies in mind.

Ray Walsh, digital privacy expert at ProPrivacysaid: “Consumers should beware of unsolicited emails that use the James Webb Space Telescope as subject and should avoid any Microsoft Office attachments containing a .jpg image, as this is used to automatically deliver the payload malicious.

“Consumers are reminded that these types of attacks rely on configuring Office to automatically run macros. We recommend that all Office users change their macro settings to warn them before running a macro, as this will help prevent malware from installing itself.

For security professionals, more details on the campaign, including Indicators of Compromise (IoC), Miter ATT&CK techniques and Yara rules, are available from Securonix.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Discover the process flow of diversity in cyber

June 3, 2023

Bringing observability to the modern data stack

June 1, 2023

How do you find the user pain points that help the mobile app succeed?

May 30, 2023
Add A Comment

Leave A Reply Cancel Reply

Latest

How to Digitize Historical School Videos

June 3, 2023

Six student loan tips for June 2023

June 3, 2023

Benson Public Schools considering Braves mascot due to new legislation – West Central Tribune

June 3, 2023

The future of entrepreneurship; why starting early is key – The Financial Express

June 3, 2023

Subscribe to Updates

Get the latest creative news from teachingresourcespro.

We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't miss

How to Digitize Historical School Videos

June 3, 2023

Six student loan tips for June 2023

June 3, 2023

Benson Public Schools considering Braves mascot due to new legislation – West Central Tribune

June 3, 2023

Subscribe to Updates

Get the latest creative news from teachingresourcespros.

  • Home
  • Contact us
  • Privacy policy
  • Terms & Conditions
© 2023 Designed by teachingresourcespro .

Type above and press Enter to search. Press Esc to cancel.