Search & Spoof: Abuse of Windows Search to Redirect to Malware
Essential information
- Published
- 11/06/2024 13:36
- Modified
- 11/06/2024 14:00
- Tags
- 2024-06-11 phishing search-ms
- Related entities
- 2 observables, 20 techniques (mitre)
Description
Trustwave SpiderLabs has uncovered a sophisticated malicious campaign that exploits the Windows search functionality embedded in HTML code to deploy malware. The campaign initiates with a suspicious email containing an HTML attachment masquerading as a routine document like an invoice. Once opened, the HTML file abuses standard web protocols to exploit Windows system functionalities, utilizing techniques such as automatic page redirection and clickable links to trigger a search exploit. By exploiting the search protocol, the attack retrieves malicious files disguised as legitimate documents from a remote server, ultimately leading to the potential execution of additional malicious operations.