New Sophisticated Credential-Stealing Malware, Forelord, Attacks the Middle East



Close-up dark keyboard with coding and programing conceptThis latest APT highlights the levels of sophistication attackers will go to just to establish persistence, infect the endpoint, and steal credentials from the victim organization.

Discovered between mid-2019 and January of this year, security researchers identified a set of spear phishing emails that contain malware attributed to a known Iranian advanced persistence threat (APT) group. Focused on organizations in Iraq, Jordan, Turkey, Azerbaijan, and Georgia, these attacks appear to be retaliation for recent geopolitical events.

The attack utilizes a significant number of steps and tools found on Windows endpoints to avoid detection by email scanning tools and endpoint antivirus. The steps are as follows:

  1. A phishing email is received
  2. The user opens a ZIP attachment
  3. The attachment contains an Excel File
  4. The user enables macros
  5. The macro opens a Command Prompt
  6. A batch file is run
  7. A PowerShell script is launched
  8. The Forelord malware is executed

Once running, Forelord downloads several of its own tools to collect credentials, test those credentials on the network, and establish an SSL tunnel to allow remote access.

As with most spear phishing attacks, the first step above is where you should place your security focus; if you stop the attack at step 1, the remainder of the attack never happens. Users educated with Security Awareness Training aren’t fooled by emails asking user to open ZIP files (who sends ZIP files these days anyways???). Instead, they are vigilant enough to spot suspicious aspects of an email (such as the odd attachment type) are don’t engage with the content – thus, stopping the attack.

Users are the key to this attack and countless others like it. Leveraging your users as part of your security defense is not only a smart move, but is a necessity to ensure the highest levels of security and lowest levels of risk.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Subscribe To Our Blog


Ransomware Has Gone Nuclear Webinar




Get the latest about social engineering

Subscribe to CyberheistNews