Security News New industrial espionage campaign leverages AutoCAD-based malware

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Researchers warn about industrial espionage group targeting companies in the energy sector with AutoCAD-based malware.

Hackers leveraged AutoCAD's scripting feature

The company said that victims usually get infected because the ZIP files with AutoCAD (.cad) projects they receive also contain hidden Fast-Load AutoLISP (.fas) modules.

These .fas modules are the equivalent of scripting components for the AutoCAD design software, akin to how macros are for Word files. The difference is that FAS modules use the Lisp programming language for its script, instead of VisualBasic or PowerShell, the preferred scripting component used with macros.
Based on the victim's AutoCAD installation settings, the AutoCAD app will either automatically execute these .fas scripting modules when the user opens the main .cad project, or when the user opens any .cad project.
Recent versions of the AutoCAD software (versions released after 2014) show warnings when executing a .fas module, but just like with the macro warnings in Office apps, some usually tend to plow through all the security alerts without thinking of the consequences and to open and view the main file's content as soon as possible.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top