HP Threat Research Blog HP Wolf Security Threat Insights Report: September 2024

September 24, 2024 Category: Threat Insights Reports By: HP Wolf Security Comments: 0

HP Wolf Security Threat Insights Report: September 2024

Welcome to the September 2024 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q2 2024.

Key Findings

  • Threat actors have been using generative artificial intelligence (GenAI) to create convincing phishing lures for some time, but there has been limited evidence of attackers using this technology to write malicious code in the wild. In Q2, however, the HP Threat Research team identified a malware campaign spreading AsyncRAT using VBScript (T1059.005) and JavaScript (T1059.007) that was highly likely to have been written with the help of GenAI. The scripts’ structure, comments and choice of function names and variables were strong clues that the threat actor used GenAI to create the malware (T1588.007). The activity shows how GenAI is accelerating attacks and lowering the bar for cybercriminals to infect endpoints.
  • ChromeLoader is a popular family of web browser malware that enables attackers to take over the victim’s browsing session and redirect searches to attackercontrolled websites. In Q2, ChromeLoader campaigns were larger and more polished, relying on malvertising (T1583.008) to direct victims to websites offering productivity tools like PDF converters. These working applications hid malicious code in MSI files (T1218.007), while valid code-signing certificates (T1553.002) helped the malware to bypass Windows security policies, increasing the chance of infection.
  • Attackers are always looking for unusual ways to infect endpoints in the hope of avoiding detection. In Q2, the HP Threat Research team identified a campaign notable for spreading malware through Scalable Vector Graphics (SVG). Widely used in graphic design, the SVG format is based on XML and supports lots of features, including scripting. The attackers abused the format’s scripting feature by embedding malicious JavaScript inside images (T1027.009), ultimately leading to multiple information stealers trying to infect the victim’s endpoint.

Read the Report

Download the report: HP Wolf Security Threat Insights Report: September 2024

Download (PDF)

You can download and read our previous Threat Insights Reports here.

About the Author

HP Wolf Security

Recent Posts

2024-09-24T17:02:12+01:00September 24th, 2024|Threat Insights Reports|