Cybercriminals use sophisticated PowerShell-based malware

Two separate threats that use malicious Windows PowerShell scripts were identified in the past few weeks by malware researchers

Cybercriminals have been developing increasingly sophisticated malware that make use of Windows PowerShell scripts in an attempt to fly under the radar.

The Windows PowerShell is a command-line shell and scripting environment designed for automating system and application administration tasks. It is installed by default in Windows 7 and above, but old versions are also available for Windows XP as a separate package.

The abuse of Windows PowerShell for malicious purposes is not new, but it seems that some capable malware developers have turned their focus to this powerful feature lately, as security researchers from both Symantec and Trend Micro have come across new and sophisticated threats that use it.

A newly identified malicious PowerShell script, which Symantec detects as Backdoor.Trojan, "has different layers of obfuscation and is able to inject malicious code into 'rundll32.exe' so that it can hide itself in the computer while still running and acting like a back door," Symantec security researcher Roberto Sponchioni said Monday in a blog post.

When run, the script compiles and executes malicious code embedded into it on the fly. The compiled code then injects more malicious code into rundll32, a system process, in order to make detection harder.

The rogue code in rundll32 connects to a remote server and waits for instructions, which it then executes in a stealthy way, Sponchioni said.

In late March, security researchers from antivirus vendor Trend Micro warned about a different threat that uses PowerShell scripts and is known as CRIGENT or Power Worm.

CRIGENT arrives in malicious Word and Excel documents that get dropped by other malware and download additional components when opened, including the Tor anonymity software and Polipo Web proxy.

"A PowerShell script (detected as VBS_CRIGENT.LK or VBS_CRIGENT.SM) is downloaded which includes all the code necessary to carry out CRIGENT's malicious behavior," the Trend Micro researchers said at the time in a blog post.

The PowerShell script also contains routines to infect clean Word and Excel documents with the malicious CRIGENT code, making the threat a self-propagating computer worm.

The combined use of Tor, Polipo, PowerShell and cloud storage services in this malware highlights the fact that cybercriminals want to use legitimate features in their attacks, the Trend Micro researchers said.

"Users should avoid running unknown PowerShell scripts and should not lower PowerShell's default execution settings in order to prevent potential malicious scripts from executing," the Symantec researchers said.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags symantectrend microsecurityDesktop securitymalware

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?