Posts

Showing posts with the label Confucius

279. The Confucius Group Uses Malicious PowerPoint Show Files

Image
Hello everyone! I love when adversaries leverage uncommon file types in their spear phishing campaigns. And I spotted another interesting example today, this time its a PPSX file. According to the report ,  The Confucius group used such files phishing email campaign targeted users in Pakistan. A PPSX file is a PowerPoint Show file created by Microsoft PowerPoint (or compatible programs like LibreOffice Impress or Google Slides). It’s a special type of PowerPoint file that opens directly in slideshow mode rather than in edit mode. It's not very common, so it may be a good idea to hunt for any suspicious files with this extension: event_type: "processcreatewin" AND proc_file_path: "powerpnt.exe" AND cmdline: *ppsx See you tomorrow!

174. Adversaries Abuse Python to Sideload a Backdoor

Image
Hello everyone! We already talked about cases, where adversaries abused Python to execute various scripts. But this time, according to Knownsec report , the Confucius group used it for sideloading. The adversary leveraged malicious LNK files (yes, again and again) to download a bunch of files to the compromised system. These files included python313.dll (a backdoor researchers called Anondoor ) and BlueAle.exe - a renamed copy of pythonw.exe . And yes, this is another case we can hunt for suspicious renamed legitimate executables: event_type: "processcreatewin" AND proc_file_originalfilename: "pythonw.exe" AND NOT proc_file_name: "pythonw.exe" Make sure to check the report for more detection ideas! See you tomorrow!