Paradise Ransomware Variant Hides in Office IQY Files

  /     /     /  
Publicated : 23/11/2024   Category : security


Paradise Ransomware Variant Hides in Office IQY Files


The uncommon Internet Query file format lets attacks slip past defenses to effectively break into target networks.



Researchers have detected an attack campaign that leverages Internet Query files (IQY) to bypass enterprise defense systems and deliver a new variant of Paradise ransomware.
Paradise has been active since 2017; now, its operators are finding new ways to deliver the malware. IQY files are simple text files read by Microsoft Excel to download data from the Internet. Its one of the lesser known weaponizable Microsoft Office file formats, Lastline researchers say. Most organizations wont block or filter IQY because its a legitimate file type. Further, the files may not register as malware because there is no payload; just a URL.
The campaign is designed to trick users into opening an IQY attachment, which retrieves a malicious Excel formula from the attackers command-and-control server. This formula contains a command to run a PowerShell command, which downloads and deploys the ransomware. Lastline researchers were able to link the executable to the Paradise ransomware family.
Researchers dont know which criminal group is responsible for this campaign; however, it is worth noting the ransomware checks to see if a machines language ID is Russian, Kazakh, Belarusian, Ukrainian, or Tatar. If one of these values is matched, the ransomware exits.
Read more details
here
.    
Check out
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays featured story:
Keys to Hiring Cybersecurity Pros When Certification Cant Help
.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Paradise Ransomware Variant Hides in Office IQY Files