216.73.217.98

Search & Spoof: Abuse of Windows Search to Redirect to Malware

· Published 11/06/2024 13:36 · Modified 11/06/2024 14:00

Export JSON

Essential information

Published
11/06/2024 13:36
Modified
11/06/2024 14:00
Tags
2024-06-11 phishing search-ms
Related entities
2 observables, 20 techniques (mitre)

Description

Trustwave SpiderLabs has uncovered a sophisticated malicious campaign that exploits the Windows search functionality embedded in HTML code to deploy malware. The campaign initiates with a suspicious email containing an HTML attachment masquerading as a routine document like an invoice. Once opened, the HTML file abuses standard web protocols to exploit Windows system functionalities, utilizing techniques such as automatic page redirection and clickable links to trigger a search exploit. By exploiting the search protocol, the attack retrieves malicious files disguised as legitimate documents from a remote server, ultimately leading to the potential execution of additional malicious operations.

External references