Security researchers recently observed a phishing campaign that uses innovative macro tactics to deliver the Ursnif banking Trojan while evading sandbox detection.

According to Trend Micro, the macro embedded into the spam email uses PowerShell’s AutoClose feature to delay execution until the document carrying the macro is closed. This allows the threat actors to elude detection tools.

A Tricky Trojan

Attackers have long used malicious macros to distribute banking Trojans and other malware, SecurityWeek reported. This particular method is designed to confuse sandboxes by disassociating the causative document from the malicious action. Like many spam campaigns, the attackers employ social engineering tricks to convince victims to enable macros manually.

The Trend Micro researchers noted that, due to its ease of implementation, this technique is “becoming a common feature is many malicious macros.”

More Tricks to Dodge Sandbox Detection

The Trend Micro team also discovered another sandbox evasion method that involves checking enumeration values, which indicate what features are present in various versions of Microsoft Office. For example, one value called xlAutomaticAllocation is only present in Office versions issued after 2007.

By checking for this value, malicious actors can determine which version of Office a victim is using. This is key, since many sandboxes only use Office 2007 for automated analysis. If the enumeration value is greater than zero, meaning that the value is active, the threat actors can be reasonably sure that they aren’t executing the malware in a sandbox.

Checking Hash Length to Hide From Sandboxes

Many detection programs also create hashes for file names they analyze. Since a hashed file name is always longer than 30 characters, the threat actors can simply check the length to determine whether their malware is in a sandbox.

The new techniques described above highlight the fact that malware authors constantly tweak their code to stay one step ahead of researchers. Security professionals must account for these tactical shifts and adjust their strategies accordingly.

more from

From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers

A comparative analysis performed by IBM Security X-Force uncovered evidence that suggests Bumblebee malware, which first appeared in the wild last year, was likely developed directly from source code associated with the Ramnit banking trojan. This newly discovered connection is particularly interesting as campaign activity has so far linked Bumblebee to affiliates of the threat group ITG23 (aka the Trickbot/Conti…