Security News > 2021 > January > 'Earth Wendigo' Hackers Exfiltrate Emails Through JavaScript Backdoor
A newly identified malware attack campaign has been exfiltrating emails from targeted organizations using a JavaScript backdoor injected into a webmail system widely used in Taiwan.
As an initial attack vector, the group used spear-phishing emails containing obfuscated JavaScript code meant to load malicious scripts from an attacker-controlled remote server.
These scripts were designed to steal browser cookies and webmail session keys, propagate the infection by appending code to the victim's email signature, and exploit a cross-site scripting vulnerability in the webmail server for JavaScript injection.
After performing the XSS injection or adding code to the Service Worker, which ensures that the malicious script is constantly loaded and executed, the attackers proceed to exfiltrate emails by establishing a WebSocket connection to an injected JavaScript backdoor.
The backdoor reads emails on the server and sends their content and attachments to the attacker's WebSocket server.
In addition to targeting webmail servers, Earth Wendigo also uses Python malware compiled as Windows executables, which were found to be shellcode loaders for code likely from Cobalt Strike.
News URL
Related news
- Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails (source)
- Salt Typhoon hackers backdoor telcos with new GhostSpider malware (source)
- RomCom hackers chained Firefox and Windows zero-days to deliver backdoor (source)
- Hackers exploit ProjectSend flaw to backdoor exposed servers (source)
- Horns&Hooves Campaign Delivers RATs via Fake Emails and JavaScript Payloads (source)
- North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks (source)
- Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses (source)
- Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor (source)
- Microsoft dangles $10K for hackers to hijack LLM email service (source)
- Winnti hackers target other threat actors with new Glutton PHP backdoor (source)