216.73.217.22

Analyzing FLUX#CONSOLE: Using Tax-Themed Lures, Threat Actors Exploit Windows Management Console to Deliver Backdoor Payloads

· Published 18/12/2024 17:16 · Modified 18/12/2024 17:37

Export JSON

Essential information

Published
18/12/2024 17:16
Modified
18/12/2024 17:37
Tags
2024-12-18 dismcore.dll dll sideloading javascript lnk files xmlhttp
Related entities
5 observables, 12 techniques (mitre), 2 others

Description

The FLUX#CONSOLE campaign involves a sophisticated tax-themed phishing attack that exploits Microsoft Management Console (MSC) files to deliver a stealthy backdoor payload. Threat actors use tax-related lures to trick users into executing malicious code. The attack leverages MSC files, which are normally used for administrative tasks, to execute obfuscated . This leads to the deployment of a malicious DLL file () through . The campaign employs advanced obfuscation techniques, including multiple layers of encoding and encryption, to evade detection. Persistence is established using scheduled tasks. The malware communicates with a command and control server, potentially exfiltrating data from infected systems.

External references