Hackers Abusing Windows Search Feature to Install Remote Access Trojans

Teilen:

A legitimate Windows search feature is being exploited by unknown malicious actors to download arbitrary payloads from remote servers and compromise targeted systems with remote access trojans such as AsyncRAT and Remcos RAT.

The novel attack technique, per Trellix, takes advantage of the search-ms: URI protocol handler, which offers the ability for applications and HTML links to launch custom local searches on a device, and the search: application protocol, a mechanism for calling the desktop search application on Windows.

Attackers are directing users to websites that exploit the ‘search-ms’ functionality using JavaScript hosted on the page, security researchers Mathanraj Thangaraju and Sijo Jacob said in a Thursday write-up. This technique has even been extended to HTML attachments, expanding the attack surface.

In such attacks, threat actors have been observed creating deceptive emails that embed hyperlinks or HTML attachments containing a URL that redirects users to compromised websites. This triggers the execution of JavaScript that makes use of the URI protocol handlers to perform searches on an attacker-controlled server.

It’s worth noting that clicking on the link also generates a warning Open Windows Explorer?, approving which the search results of remotely hosted malicious shortcut files are displayed in Windows Explorer disguised as PDFs or other trusted icons, just like local search results, the researchers explained.

This smart technique conceals the fact that the user is being provided with remote files and gives the user the illusion of trust. As a result, the user is more likely to open the file, assuming it is from their own system, and unknowingly execute malicious code.

Should a victim click on one of the shortcut files, it leads to the execution of a rogue dynamic-link library (DLL) using the regsvr32.exe utility.

In an alternative variant of the campaign, the shortcut files are employed to run PowerShell scripts, which, in turn, download additional payloads in the background, while displaying a decoy PDF document to deceive victims.

Regardless of the method used, the infections lead to the installation of AsyncRAT and Remcos RAT, offering a pathway for threat actors to remotely commandeer the hosts, steal sensitive information, and even sell the access to other attackers.

With Microsoft steadily taking steps to clamp down on various initial access vectors, it’s expected that adversaries could latch onto the URI protocol handler method to evade traditional security defenses and distribute malware.

It is crucial to refrain from clicking on suspicious URLs or downloading files from unknown sources, as these actions can expose systems to malicious payloads delivered through the ‘search’ / ‘search-ms’ URI protocol handler, the researchers said.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:08 am, Mai 24, 2025
Wetter-Symbol 13°C
L: 13° | H: 14°
light rain
Luftfeuchtigkeit: 90 %
Druck: 1012 mb
Wind: 7 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.12 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0.43 mm 43% 13 mph 92 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 10 mph 92 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 22°°C 0 mm 0% 13 mph 70 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.25 mm 25% 16 mph 75 % 1007 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,191.65
-2.28%
Ethereum(ETH)
€2,243.30
-5.23%
Fesseln(USDT)
€0.88
0.03%
XRP(XRP)
€2.06
-4.65%
Solana(SOL)
€153.95
-3.72%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.200812
-7.69%
Shiba Inu(SHIB)
€0.000012
-7.36%
Pepe(PEPE)
€0.000012
-10.93%
Peanut das Eichhörnchen(PNUT)
€0.307496
-7.39%
Nach oben scrollen