HPQ HP Inc.

Malware ‘Meal Kits’ Are Helping Attackers Steal Businesses’ Lunch, HP Finds

Malware ‘Meal Kits’ Are Helping Attackers Steal Businesses’ Lunch, HP Finds

Pre-packaged malware kits give attackers all the ingredients to evade detection tools, making it easier to breach organizations and steal sensitive data

PALO ALTO, Calif., Oct. 31, 2023 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) today issued its quarterly showing that thriving cybercriminal marketplaces are offering low-level attackers the tools needed to bypass detection and infect users.

Based on data from millions of endpoints running HP Wolf Security, key findings include:

  • Houdini’s Last Act: A new campaign targeted businesses with fake shipping documents concealing Vjw0rm JavaScript malware. Its obfuscated code allowed the malware to slip past email defenses and reach endpoints. The analyzed attack delivered Houdini, a 10-year-old VBScript RAT. This shows that, with the right pre-packaged tools from cybercrime marketplaces, hackers can still use vintage malware effectively by abusing the scripting features built into operating systems.
  • Cybercriminals Deploy “Jekyll and Hyde” Attacks: HP discovered a Parallax RAT campaign launching two threads when a user opens a malicious scanned invoice designed to trick users. The “Jekyll” thread opens a decoy invoice copied from a legitimate online template, reducing suspicion, while the “Hyde” runs the malware in the background. This attack would be easy for threat actors to carry out, as pre-packaged Parallax kits have been advertised on hacking forums for

Alex Holland, Senior Malware Analyst in the HP Wolf Security threat research team, comments:

"Threat actors today can easily purchase pre-packaged, user-friendly malware ‘meal kits’, that infect systems with a single click. Instead of creating their own tools, low-level cybercriminals can access kits that use living-off-the-land tactics. These stealthy in-memory attacks are often harder to detect due to security tool exclusions for admin use, like automation.”

HP also identified attackers are “hazing” aspiring cybercriminals by hosting fake malware building kits on code sharing platforms like GitHub. These malicious code repositories trick wannabe threat actors into infecting their own machines. One popular malware kit, XWorm, is advertised on underground markets for as much as $500 USD, driving resource-strapped cybercriminals to buy fake cracked versions.

By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely – HP Wolf Security has specific insight into the latest techniques used by cybercriminals in the fast-changing cybercrime landscape. To date, HP Wolf Security customers have clicked on over 30 billion email attachments, web pages, and downloaded files with no reported breaches.

The report details how cybercriminals continue to diversify attack methods to bypass security policies and detection tools. Other findings include:

  • Archives were the most popular malware delivery type for the sixth quarter running, used in 36% of cases analyzed by HP.
  • Despite being disabled by default, macro-enabled Excel add-in threats (.xlam) rose to the 7th most popular file extension abused by attackers in Q3, up from 46th place in Q2. Q3 also saw malware campaigns abusing PowerPoint add-ins.
  • At least 12% of email threats identified by HP Sure Click bypassed one or more email gateway scanner in both Q3, and Q2.
  • Q3 saw an increase in attacks using exploits in Excel (91%) and Word (68%) formats.
  • There was a 5%-point rise in PDF threats isolated by HP Wolf Security compared to Q2.
  • The top threat vectors in Q3 were email (80%) and downloads from browsers (11%).

“While the tools for crafting stealthy attacks are readily available, threat actors still rely on the user clicking,” continues Alex Holland. “To neutralize the risk of pre-packaged malware kits, businesses should isolate high-risk activities, like opening email attachments, link clicks, and downloads. This significantly minimizes the potential for a breach by reducing the attack surface."

HP Wolf Security runs risky tasks in isolated, hardware-enforced virtual machines running on the endpoint to protect users, without impacting their productivity. It also captures detailed traces of attempted infections. HP’s application isolation technology mitigates threats that slip past other security tools and provides unique insights into intrusion techniques and threat actor behavior.

About the data

This data was gathered from consenting HP Wolf Security customers from July-September 2023.

About HP

HP Inc. (NYSE: HPQ) is a global technology leader and creator of solutions that enable people to bring their ideas to life and connect to the things that matter most. Operating in more than 170 countries, HP delivers a wide range of innovative and sustainable devices, services and subscriptions for personal computing, printing, 3D printing, hybrid work, gaming, and more. For more information, please visit: .

About HP Wolf Security

HP Wolf Security is a new breed of endpoint security. HP’s portfolio of hardware-enforced security and endpoint-focused security services are designed to help organizations safeguard PCs, printers, and people from circling cyber predators. HP Wolf Security provides comprehensive endpoint protection and resiliency that starts at the hardware level and extends across software and services. Visit

HP Media Relations



 



EN
31/10/2023

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on HP Inc.

 PRESS RELEASE

HP Inc. Declares Dividend

HP Inc. Declares Dividend PALO ALTO, Calif., May 14, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) has declared a cash dividend of $0.2894 per share on the company’s common stock. The dividend, the third in HP’s fiscal year 2025, is payable on July 2, 2025, to stockholders of record as of the close of business on June 11, 2025. HP has approximately 0.9 billion shares of common stock outstanding. About HP Inc. HP Inc. (NYSE: HPQ) is a global technology leader and creator of solutions that enable people to bring their ideas to life and connect to the things that matter most. Operating in ...

 PRESS RELEASE

HP Inc. to Announce Second Quarter Fiscal 2025 Earnings on May 28, 202...

HP Inc. to Announce Second Quarter Fiscal 2025 Earnings on May 28, 2025 PALO ALTO, Calif., May 06, 2025 (GLOBE NEWSWIRE) -- HP Inc. (NYSE: HPQ) will present a live audio webcast of a conference call to review financial results for the second fiscal quarter ended April 30, 2025 on Wednesday, May 28, 2025 at 5:00 p.m. ET / 2:00 p.m. PT. The webcast will be available at . A replay of the audio webcast will be available at the same website shortly after the call and will remain available for approximately one year. About HP Inc. HP Inc. (NYSE: HPQ) is a global technology leader a...

 PRESS RELEASE

Lewis Hamilton Foundation Mission 44 and HP Inc. Join Forces to Drive ...

Lewis Hamilton Foundation Mission 44 and HP Inc. Join Forces to Drive STEM Skills and Future of Work Readiness for Young People MIAMI, May 01, 2025 (GLOBE NEWSWIRE) -- Today at the F1 Miami Grand Prix circuit, Sir Lewis Hamilton’s global foundation Mission 44 and HP Inc. (NYSE: HPQ) announced a multi-year partnership to fuel access to technology and skills needed to pursue careers in science, technology, engineering, and mathematics. This collaboration unites Mission 44’s drive for greater inclusivity in STEM with HP’s ambition to accelerate digital equity for 150 million people globally ...

 PRESS RELEASE

Scuderia Ferrari and HP Fuse Technology and Design with Special Livery...

Scuderia Ferrari and HP Fuse Technology and Design with Special Livery for Miami Grand Prix News Highlights: Scuderia Ferrari and HP collaborate to co-engineer livery wrapping technologies pushing the boundaries of design possibilities in the near futureDebut of special edition livery for Miami GP to mark the first year of title partnershipWith the latest-generation HP technology, Ferrari is building the working environment of the future in Maranello and at the track MIAMI, Fla., April 30, 2025 (GLOBE NEWSWIRE) -- Scuderia Ferrari and HP Inc. (NYSE: HPQ) today revealed a special co-desi...

 PRESS RELEASE

UPDATE -- HP Announces 2025 Digital Equity Accelerator Cohort

UPDATE -- HP Announces 2025 Digital Equity Accelerator Cohort Selected nonprofit organizations are accelerating digital equity and powering the future of work in Greece, Indonesia, Nigeria, and Spain for disconnected communities News Highlights: Eight nonprofit organizations in Greece, Indonesia, Nigeria, and Spain selected for the 2025 Digital Equity Accelerator.Organizations are serving disconnected adolescents and adults through digital skills training, education access, and other community-driven initiatives.Each nonprofit will receive $100,000 of HP technology and solutions, capacit...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch