• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ongoing phishing and malware campaigns in december 2024

Ongoing Phishing and Malware Campaigns in December 2024

You are here: Home / General Cyber Security News / Ongoing Phishing and Malware Campaigns in December 2024
December 10, 2024

Cyber attackers never stop inventing new ways to compromise their targets. That’s why organizations must stay updated on the latest threats.

Here’s a quick rundown of the current malware and phishing attacks you need to know about to safeguard your infrastructure before they reach you.

Zero-day Attack: Corrupted Malicious Files Evade Detection by Most Security Systems

The analyst team at ANY.RUN recently shared their analysis of an ongoing zero-day attack. It has been active since at least August and still remains unaddressed by most detection software to this day.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The attack involves the use of intentionally corrupted Word documents and ZIP archives with malicious files inside.

VirusTotal shows 0 detections for one of the corrupted files

Due to corruption, security systems cannot properly identify the type of these files and run analysis on them, which results in zero threat detections.

Once these files are delivered to a system and opened with their native applications (Word for docx and WinRAR for zip) they get restored, presenting the victim with malicious contents.

The ANY.RUN sandbox is one of the few tools that detect this threat. It allows users to manually open corrupted malicious files inside a fully interactive cloud VM with their corresponding apps and restore them. This enables you to see what kind of payload the file contains.

Check out this sandbox session featuring a corrupted Word document. After recovery, we can see that there is a QR code with an embedded phishing link.

The sandbox automatically identifies malicious activity and notifies you about this.

Try ANY.RUN’s Interactive Sandbox to see how it can speed up and improve your malware analysis.

Get a 14-day trial to test all of its advanced features for free →

Fileless Malware Attack via PowerShell Script Distributes Quasar RAT

Another notable recent attack involves the use of a fileless loader called Psloramyra, which drops Quasar RAT onto infected devices.

This sandbox session shows how, after taking initial foothold on the system, Psloramyra loader employs a LoLBaS (Living off the Land Binaries and Scripts) technique to launch a PowerShell script.

The script loads a malicious payload dynamically into memory, identifies and utilizes the Execute method from the loaded .NET assembly, and finally injects Quasar into a legitimate process like RegSvcs.exe.

The malware functions entirely within the system’s memory, ensuring it leaves no traces on the physical disk. To maintain its presence, it creates a scheduled task that runs every two minutes.

Abuse of Azure Blob Storage in Phishing Attacks

Cybercriminals are now hosting phishing pages on Azure’s cloud storage solution, leveraging the *.blob[.]core[.]windows[.]net subdomain.

Attackers use a script to fetch information about the victim’s software, such as the OS and browser, which is on the page to make it appear more trustworthy. See example.

The objective of the attack is to trick the victim into entering their login credentials into a fake form, which are then collected and exfiltrated.

Emmenhtal Loader Uses Scripts to Deliver Lumma, Amadey, and Other Malware

Emmenhtal is an emerging threat that has been involved in several campaigns over the past year. In one of the latest attacks, criminals utilize scripts to facilitate the execution chain that involves the following steps:

  • LNK file initiates Forfiles
  • Forfiles locates HelpPane
  • PowerShell launches Mshta with the AES-encrypted first-stage payload
  • Mshta decrypts and executes the downloaded payload
  • PowerShell runs an AES-encrypted command to decrypt Emmenhtal

The Emmenhtal loader, which is the final PowerShell script, executes a payload — often Updater.exe — by using a binary file with a generated name as an argument.

This leads to infection by malware families like Lumma, Amadey, Hijackloader, or Arechclient2.

Analyze Latest Cyber Attacks with ANY.RUN

Equip yourself with ANY.RUN’s Interactive Sandbox for advanced malware and phishing analysis. The cloud-based service provides you with a safe and fully-functional VM environment, letting you freely engage with malicious files and URLs you submit.

It also automatically detects malicious behavior in real time across network and system activities.

  • Identify threats in < 40 seconds
  • Save resources on setup and maintenance
  • Log and examine all malicious activities
  • Work in private mode with your team

Get a 14-day free trial of ANY.RUN to test all the features it offers →

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cert ua warns of phishing attacks targeting ukraine's defense and security CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force
Next Post: Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage hackers weaponize visual studio code remote tunnels for cyber espionage»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.