Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT

Summary
AhnLab reports phishing emails impersonating employees of a Korean company. A disguised XLS exploits CVE-2017-0199 to run a chain that ultimately installs Remcos RAT, which can collect information and execute remote commands.
Key points
- The emails impersonate employees and use a project-material purchase request as a lure to get recipients to open an attached XLS file.
- The XLS exploits the OLE2Link vulnerability CVE-2017-0199 to retrieve and execute a malicious HTA file.
- The HTA uses WMI to run an obfuscated PowerShell script, which extracts a .NET loader hidden in a PNG using steganography.
- The loader downloads and executes Remcos RAT.
- Remcos can execute remote commands, collect system and user information, capture keystrokes and screens, and manipulate files.
- AhnLab advises verifying sender addresses and URLs and treating unexpected attachments and requests for sensitive information with caution.
Article Details
- Attack Vectors
- Phishing emails impersonate employees of a company in Korea and attach an XLS file disguised as a project material purchase request.
- Opening the XLS file triggers CVE-2017-0199 through its OLE2Link content, causing Microsoft Office to download and execute a malicious HTA file.
- The HTA file uses WMI to launch an obfuscated PowerShell script. The script retrieves a steganographic PNG, extracts and decrypts an embedded .NET loader, and executes it in memory. The loader then downloads Remcos RAT.
- Defensive Notes
- Verify that the sender's email address uses the organization's official domain.
- Inspect links before clicking and check attachments for suspicious file extensions.
- Verify a website's URL before entering credentials or other sensitive information; do not enter them on a suspicious page.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | blessedongrace[.]duckdns[.]org | Remcos RAT C2 host, listed with port 19700. |
| MD5 | 5055c7b0ae1f6f77b16eb744a76cc453 | MD5 hash listed among the article's threat indicators; the associated file is not specified. |
| MD5 | 623bc9114d118592170599585e5cf60e | MD5 hash listed among the article's threat indicators; the associated file is not specified. |
| MD5 | db9ff235eae552276b12622ae9105f1c | MD5 hash listed among the article's threat indicators; the associated file is not specified. |
| URL | hxxp[:]//172[.]245[.]209[.]133/70/Img_201031[.]Png | URL identified as the Remcos RAT download C2. |
| URL | hxxp[:]//172[.]245[.]209[.]133/70/img_201031[.]png | URL listed as a Remcos RAT download indicator. |
| URL | hxxp[:]//172[.]245[.]209[.]133/70/Weprovideforbesthingstocomebackgoodthings[.]Hta | C2 URL used to download the malicious HTA file. |
| URL | hxxp[:]//172[.]245[.]209[.]133/70/weprovideforbesthingstocomebackgoodthings[.]hta | URL listed as a malicious HTA download indicator. |
| URL | hxxp[:]//blessedongrace[.]duckdns[.]org/ | URL listed for the Remcos RAT C2 host. |
| URL | hxxp[:]//muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev/HIsPq | URL used to download the steganographic PNG containing an encoded loader. |
| URL | hxxps[:]//muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev/HIsPq | URL listed for the steganographic PNG download. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe HTA launches an obfuscated PowerShell script, and the downloaded PNG contains an encoded, encrypted loader.T1027.003 · SteganographyA downloaded PNG conceals a Base64-encoded .NET loader that the PowerShell script extracts.T1041 · Exfiltration Over C2 ChannelThe article states that Remcos RAT transmits collected information and execution results through communication with its C2 server.T1047 · Windows Management InstrumentationThe HTA file uses WMI's Win32_Process.Create() method to execute an obfuscated PowerShell script.T1056.001 · KeyloggingThe article states that Remcos RAT can collect information through keylogging.T1059.001 · PowerShellThe malicious HTA file launches a PowerShell script in the background.T1105 · Ingress Tool TransferThe attack downloads a malicious HTA file, a PNG containing a loader, and Remcos RAT from external servers.T1113 · Screen CaptureThe article states that Remcos RAT can capture the infected system's screen.T1140 · Deobfuscate/Decode Files or InformationThe PowerShell script extracts and decrypts the loader embedded in the PNG before executing it.T1203 · Exploitation for Client ExecutionOpening the XLS file exploits CVE-2017-0199 in Microsoft Office to download and execute a malicious HTA file.T1566.001 · Spearphishing AttachmentThe phishing emails attach a malicious XLS file disguised as a project material purchase request.