Close Menu
  • Science
  • Techonology
    • AI
    • Tech News
  • Finance
  • Contact US
  • More
    • About Us
    • Privacy Policy
    • Disclaimers
    • Terms and Conditions

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Knicks frustrated as lapses on defense put them in 2-0 hole

May 25, 2025

The Bombing of Pan Am 103 review – this kind, cheesy Lockerbie show just doesn’t work as TV | Television

May 25, 2025

Rudy Gobert is crushing the Timberwolves in the most expected way

May 25, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Vimeo
SkyMagzines
Subscribe Login
  • Home
  • News

    Breaking: Joe Biden Diagnosed with Advanced Prostate Cancer – Former President Faces Aggressive Hormone-Sensitive Diagnosis

    May 19, 2025

    The Impact of the Recent Caribbean Earthquake: What You Need to Know

    February 9, 2025

    Tragedy Strikes as Hugh Douglas, Son of Former Eagles Defender and 94.1 WIP Host, Killed in Car Crash

    September 6, 2023

    What is Labor Day – A Celebration of Workers’ Contributions

    September 4, 2023
  • Lifestyle
  • Privacy Policy
  • DCAM Policy
  • Terms and Conditions
  • Contact US
SkyMagzines
  • Home
  • Technology
  • World
  • Lifestyle
Home » Hackers use new PowerMagic and CommonMagic malware to steal data
Tech News

Hackers use new PowerMagic and CommonMagic malware to steal data

Sky MagzinesBy Sky MagzinesAugust 28, 2023Updated:August 28, 2023No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers have discovered attacks from an advanced threat actor that used “a previously unseen malicious framework” called CommonMagic and a new backdoor called PowerMagic.

Both malware pieces have been used since at least September 2021 in operations that continue to this day and target organizations in the administrative, agriculture, and transportation sectors for espionage purposes.

New malicious toolkit dropped

Researchers at cybersecurity company Kaspersky say that the hackers are interested in collecting data from victims in Donetsk, Lugansk, and Crimea.

Once inside the victim network, the attackers behind the CommonMagic espionage campaign can use separate plugins to steal documents and files (DOC, DOCX, XLS, XLSX, RTF, ODT, ODS, ZIP, RAR, TXT, PDF) from USB devices.

The malware used can also take screenshots every three seconds using the Windows Graphics Device Interface (GDI) API.

The researchers believe that the initial infection vector is spear phishing or a similar method to deliver a URL pointing to a ZIP archive with a malicious LNK file.

A decoy document (PDF, XLSX, DOCX) in the archive diverted the target user from the malicious activity that started in the background when the LNK file disguised as a PDF was launched.

Malicious ZIP delivered in CommonMagic campaign
Malicious ZIP delivered in CommonMagic campaign

Kaspersky says that activating the malicious LNK would lead to infecting the system with a previously unknown PowerShell-based backdoor that the researcher named PowerMagic after a string in the malware code.

The backdoor communicates with the command and control (C2) server to receive instructions and upload the results using OneDrive and Dropbox folders.

Following the PowerMagic infection, the targets were infected with CommonMagic, a collection of malicious tools that the researchers have not seen before these attacks.

CommonMagic infection chain
CommonMagic infection chain
source: Kaspersky

The CommonMagic framework has several modules that start as standalone executables and use named pipes to communicate.

Kaspersky’s analysis revealed that the hackers created dedicated modules for various tasks, from interacting with the C2 to encrypting and decrypting traffic from the command server, stealing documents, and taking screenshots.

Modular architecture of the CommonMagic framework
Architecture of the modular CommonMagic framework
source: Kaspersky

Exchanging data with the C2 is also done via a OneDrive folder and the files are encrypted using the RC5Simple open-source library with a customized sequence – Hwo7X8p – at the beginning of the encryption.

Hiding behind ordinary tactics

The malware or the methods seen in CommonMagic attacks are not complex or innovative. An infection chain involving malicious LNK files in ZIP archives has been observed with multiple threat actors.

Incident response firm Security Joes announced last month the discovery of a new backdoor called IceBreaker that was delivered from a malicious LNK in a ZIP archive.

A similar method was seen in a ChromeLoader campaign that relied on a malicious LNK to execute a batch script and extract the content of a ZIP container to fetch the final payload.

However, the closest to CommonMagic’s technique is a threat actor that Cisco Talos tracks as YoroTrooper, who engaged in cyberespionage activity using phishing emails delivering malicious LNK files and decoy PDF documents encased in a ZIP or RAR archive.

Despite the non-customary approach, though, CommonMagic’s method proved to be successful, Kaspersky says.

The researchers discovered an active infection in October last year but tracked a few attacks from this threat actor as old as September 2021.

Leonid Besverzhenko, security researcher at Kaspersky’s Global Research and Analysis Team, told BleepingComputer that the PowerMagic backdoor and the CommonMagic framework were used in dozens of attacks.

Although CommonMagic activity appears to have started in 2021, Besverzhenko says that the adversary intensified their efforts last year and continues to be active today.

By combining unsophisticated techniques that have been used by multiple actors and original malicious code, the hackers managed to make impossible a connection to other campaigns at this time.

A spokesperson from Kaspersky told BleepingComputer that “the limited victimology and Russian-Ukrainian conflict-themed lures suggest that the attackers likely have a specific interest in the geopolitical situation in that region.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleMICROSOFT SAYS OPENAI’S LATEST BLOCKBUSTER AI IS DROPPING “NEXT WEEK”
Next Article Microsoft brings OpenAI’s DALL-E image creator to the new Bing
Sky Magzines
  • Website
  • Tumblr
  • LinkedIn

If You Want To Ask Any Question... Let Us Know in Comment Section.

Related Posts

How AI Is Disrupting The HR Tech Marketplace According to Josh Bersin

August 28, 2023

Elon musk whines that buying twitter has been emotionally “painful”.

August 28, 2023

Company builds facility that lifts and lowers 24-Ton bricks to store energy.

August 28, 2023

Elon Musk Lost $13 Billion on 4/20

August 28, 2023
Leave A Reply Cancel Reply

Knicks frustrated as lapses on defense put them in 2-0 hole

May 25, 2025

The Bombing of Pan Am 103 review – this kind, cheesy Lockerbie show just doesn’t work as TV | Television

May 25, 2025

Rudy Gobert is crushing the Timberwolves in the most expected way

May 25, 2025

Every Upcoming John Wick Spin-Off Explained

May 25, 2025
Top Posts

Steve Wozniak: If you want to learn about AI killing people, “Get a Tesla”

August 28, 202313,444 Views

OpenAI CEO Predicted AI Would Either End the World as We Know It, or Make Tons of Money

August 28, 20236,525 Views

RESEARCHERS SUCCESSFULLY TURN ABANDONED OIL WELL INTO GIANT GEOTHERMAL BATTERY

August 28, 20233,064 Views

Elon musk buys ten thousand GPUs for secretive AI project

August 28, 20232,846 Views
Don't Miss
World News

Knicks frustrated as lapses on defense put them in 2-0 hole

By Sky MagzinesMay 25, 20250

NEW YORK — One game after the Knicks historically blew a playoff lead with three…

The Bombing of Pan Am 103 review – this kind, cheesy Lockerbie show just doesn’t work as TV | Television

May 25, 2025

Rudy Gobert is crushing the Timberwolves in the most expected way

May 25, 2025

Every Upcoming John Wick Spin-Off Explained

May 25, 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

About Us

Your source for the lifestyle news. This demo is crafted specifically to exhibit the use of the theme as a lifestyle site. Visit our main page for more demos.

We're accepting new partnerships right now.

Email Us: info@skymagines.com
Contact: +1-320-0123-451

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Knicks frustrated as lapses on defense put them in 2-0 hole

May 25, 2025

The Bombing of Pan Am 103 review – this kind, cheesy Lockerbie show just doesn’t work as TV | Television

May 25, 2025
Most Popular

What Is Fiat Money?

August 28, 20230 Views

Best Construction Loan Lenders

August 28, 20230 Views
Facebook X (Twitter) Instagram Pinterest
  • Home
  • Technology
  • World
  • Lifestyle
© 2025 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?