OfflRouter Malware Evades Detection in Ukraine for Almost a Decade
ID: e278669e-df52-5ec7-953f-5d49d44942bd
STIX ID: report--e278669e-df52-5ec7-953f-5d49d44942bd
Feed Name: The Hacker News
Cisco Talos analysis indicates an ongoing, low-noise malware campaign named OfflRouter active in Ukraine since 2015 that uses VBA macro-infected .DOC files (and/or a standalone ctrlpanel.exe) to drop a .NET executable which infects .DOC files, copies/executes plugin files on removable media (.ORP), and achieves persistence via Windows Registry modifications; propagation is primarily via manual sharing and removable media rather than automated email, limiting scale but resulting in confidential documents being uploaded to public repositories and continued detections on VirusTotal since 2018.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
