Rewterz
Rewterz Threat Alert – New Version of Stantinko Group Linux Proxy Trojan Masquerades as httpd
November 25, 2020
Rewterz
Rewterz Threat Alert – TrickBot Employs Clever New Obfuscation Trick to evade detection
November 26, 2020

Rewterz Threat Alert – Russian APT Gamaredon Using Template Injection

Severity

High

Analysis Summary

Gamaredon, the Russia-backed advanced persistent threat (APT) threat actor that has been active since at least 2013 has reinforced its cyber warfare activities a new surge of Gamaredon APT attacks targeting users with template injection of malicious documents exploiting Microsoft Word vulnerability CVE-2017-0199. Attacker main target is to get control of the target system using the malicious document.The exploit document employs the template injection technique to install additional malware on the victim’s machine. Upon opening the document, it connects back to the hacker’s server to download the payload file.

Image
Image

Impact

  • Code Execution 
  • Data Manipulation 
  • Device take over

Indicators of Compromise

MD5

  • b841990b6f15fa26bbbb11e217229bf7

SHA-256

  • c6fe85f16ddb68f8244e8a6518f02b998e15cbd94a56ef756cf14c36c82a2e2b

SHA1

  • 8cf958b088d5cb3b1695f303df6decbe23b03cf2

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment