New Sophisticated Credential-Stealing Malware, Forelord, Attacks the Middle East

Stu Sjouwerman | Mar 4, 2020

Close-up dark keyboard with coding and programing conceptThis latest APT highlights the levels of sophistication attackers will go to just to establish persistence, infect the endpoint, and steal credentials from the victim organization.

Discovered between mid-2019 and January of this year, security researchers identified a set of spear phishing emails that contain malware attributed to a known Iranian advanced persistence threat (APT) group. Focused on organizations in Iraq, Jordan, Turkey, Azerbaijan, and Georgia, these attacks appear to be retaliation for recent geopolitical events.

The attack utilizes a significant number of steps and tools found on Windows endpoints to avoid detection by email scanning tools and endpoint antivirus. The steps are as follows:

  1. A phishing email is received
  2. The user opens a ZIP attachment
  3. The attachment contains an Excel File
  4. The user enables macros
  5. The macro opens a Command Prompt
  6. A batch file is run
  7. A PowerShell script is launched
  8. The Forelord malware is executed

Once running, Forelord downloads several of its own tools to collect credentials, test those credentials on the network, and establish an SSL tunnel to allow remote access.

As with most spear phishing attacks, the first step above is where you should place your security focus; if you stop the attack at step 1, the remainder of the attack never happens. Users educated with Security Awareness Training aren’t fooled by emails asking user to open ZIP files (who sends ZIP files these days anyways???). Instead, they are vigilant enough to spot suspicious aspects of an email (such as the odd attachment type) are don’t engage with the content – thus, stopping the attack.

Users are the key to this attack and countless others like it. Leveraging your users as part of your security defense is not only a smart move, but is a necessity to ensure the highest levels of security and lowest levels of risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.