New “Executive Award” Scam Exploits ClickFix to Deliver Stealerium Malware
## Cybersecurity: Phishing Campaign Targeting Executives
Cybersecurity: Phishing Campaign Targeting Executives
A recent phishing campaign targets company executives with a sophisticated attack that combines credential theft and information-stealing malware deployment. This dual-pronged threat has been identified by cybersecurity researchers at Trustwave MailMarshal.
The campaign, known as the "Executive Award" scam, initiates with a phishing email impersonating the "Cartier Recognition Program." This email presents an executive recognition award and includes a password-protected ZIP file with personalized details. Recipients are encouraged to open a "secure digital package" to claim their award, initiating a two-stage attack sequence.
The first stage involves a standalone HTML phishing page named "Virtual-Gift-Card-Claim.html," which mimics a webmail login interface for the victim's domain. Entered credentials are exfiltrated to a Telegram command-and-control channel, potentially granting attackers access to corporate email accounts.
ClickFix Technique and Stealerium Deployment
The second stage utilizes the ClickFix technique to install the Stealerium malware. Users encounter a malicious SVG file named "account-verification-form.svg" that displays a fake Google Chrome error message. This message advises running a PowerShell "fix" command, a technique exploiting user trust.
Executing the suggested command triggers a sophisticated PowerShell chain that downloads and installs Stealerium through multiple loader stages. This process circumvents traditional security measures.
This dual-pronged threat has been identified by cybersecurity researchers at Trustwave MailMarshal.
Stealerium is capable of extracting browser passwords, cryptocurrency wallets, system information, and other sensitive data. The collected information is sent to attacker-controlled servers, offering cybercriminals a detailed victim profile and potential access to financial accounts.
Researchers have identified the attack infrastructure centered around IP address 31.57.147.77, which hosts multiple payload delivery endpoints. The campaign uses separate Telegram bot channels for phished credentials and Stealerium data, showcasing a compartmentalized approach.
The Stealerium command-and-control server uses a hardcoded encryption key "StealeriumC2SecretKey123" for secure communications. To mitigate this threat, organizations should implement application allowlisting and restrict PowerShell execution.
It is recommended to use email security filters to flag suspicious attachments, particularly password-protected archives and HTML files. Employee training should be conducted to raise awareness about unsolicited awards and credential phishing attempts.
Security teams are advised to block identified indicators of compromise, including malicious file hashes and attacker IP infrastructure. This campaign highlights the integration of multiple techniques to achieve credential theft and malware infection within a single operation.
Based on reporting by GBHackers.
