Security researchers at Trustwave spotted a new malicious campaign that uses a multi-stage attack to deploy a password stealer malware. Hackers leverage the infamous Necurs botnet to distribute spam emails delivering Microsoft Office documents that embedded malicious macros. The malware steals credentials from email, ftp, and browser programs by concatenating available strings in the memory and usage of the APIs RegOpenKeyExW and PathFileExistsW to check if registry or paths of various programs exist. The most interesting aspect of this attack is the use of multiple stages to deliver the final payload.”]
Source: https://securityaffairs.co/wordpress/69310/breaking-news/multi-stage-attack.html

