• About
  • Privacy
  • Terms
  • Contact
Thursday, September 21, 2023
News Cryptos
  • Home
  • Bitcoin
  • Ethereum
  • Altcoin
  • DeFi
  • Gaming
  • NFT
  • Blockchain
No Result
View All Result
News Cryptos
  • Home
  • Bitcoin
  • Ethereum
  • Altcoin
  • DeFi
  • Gaming
  • NFT
  • Blockchain
No Result
View All Result
News Cryptos
No Result
View All Result

More malicious attachments found by researchers | IT World Canada News

Crypto Moose by Crypto Moose
September 16, 2023
in Canada
Reading Time: 3 mins read
A A
0


Attachments continue to be an effective way of delivering malware as long as employees miss vital clues. Two examples detailed by researchers at Fortinet demonstrate the latest techniques of threat actors that can be shown to staff as part of security awareness training.

The first is a Word document containing a malicious URL designed to entice victims to download a malware loader. The payloads of this loader include OriginBotnet for keylogging and password recovery, RedLine Clipper for stealing cryptocurrency on a victim’s computer and AgentTesla for harvesting sensitive information.

The example found by Fortinet is a financial document, but an attacker could use any tactic: A resume, a request for proposal, etc. Clicking on the Word document results in the display of a deliberately blurred image to convince the recipient there is a document to be seen if they also click on a counterfeit  but standard-looking reCAPTCHA challenge that says “I am not a robot.” That starts a process for loading the malware.

This blurred image and re:Captcha form pops up when document is clicked on. Image from Fortinet

RedLine Clipper, also known as ClipBanker, steals cryptocurrencies by manipulating the user’s system clipboard activities to substitute the destination wallet address with one belonging to the attacker. Due to the complexity of digital wallet addresses, users often copy and paste them during transactions.

Agent Tesla can log keystrokes, access the host’s clipboard, and conduct disk scans to uncover credentials and other valuable data. It transmits gathered information to a Command and Control (C2) server through several communication channels, including HTTP(S), SMTP, FTP, or even by dispatching it to a designated Telegram channel.

OriginBotnet has a range of capabilities including collecting sensitive data, establishing communications with its C2 server, and downloading additional files from the server to execute keylogging or password recovery functions on compromised computers.

The second example is a file the researchers obtained that they assume was an attachment because it purports to be a list of company officers. The email message might have claimed to be a corporate instruction for employees. The format of this attachment is a compressed .RAR file. Clicking on it reveals two components: A PDF named “Notice to Work-From-Home groups.” If a victim clicks on it, an image of an error message pops up that falsely indicates that the PDF document failed to load.

Screen shot of decoy error message
This error message is a diversion

This is actually a decoy, according to Fortinet, that is supposed to encourage the victim to click on the second file, “062023_PENTING_LIST OF SUPERVISORY OFFICERS WHO STILL HAVE NOT REPORT.pdf.exe.” For staff who have good awareness training, this file’s .exe extension should be a warning that it not be clicked on. That assumes the full file name shows. However, the report notes, by default Windows doesn’t show full file names. The threat actor uses this knowledge in hopes of disguising the file so the victim will think it’s a PDF and not a file that executes.

The purpose of this file is to act as a dropper for several pieces of malware.

Cybersecurity experts say that employee awareness training is vital to a broad defence strategy. Including examples is one way to help them learn.





Source link

Tags: Canada
TweetShareSendShareShareSharePinSend
Previous Post

Solana Price Prediction as SOL Bounces 4% Overnight – Is the Sell-Off Over?

Next Post

Former FTX exec Ryan Salame to forfeit $1.5 billion after guilty plea: CNBC Crypto World

Bullet Blockchain Retains Law Firm to Pursue Unlicensed Violators of The Company’s Bitcoin ATM Intellectual Property
Canada

Bullet Blockchain Retains Law Firm to Pursue Unlicensed Violators of The Company’s Bitcoin ATM Intellectual Property

by Crypto Moose
September 18, 2023

The Law Offices of J.S. Hindi has been retained to target unlicensed Bitcoin ATM operators and seek justice for consumers through litigation against violators Bullet Blockchain’s Intellectual Property Portfolio is...

Read more
Next Big Crypto to Buy Now | Analyzing the Best High Growth Crypto Coins With Huge Potential in 2023 and New Emerging Tokens.

Next Big Crypto to Buy Now | Analyzing the Best High Growth Crypto Coins With Huge Potential in 2023 and New Emerging Tokens.

September 18, 2023
Best Meme Coins to Buy Now | The Ultimate Guide to Top Crypto Presales and New Meme Coins with ApeMax, Wall Street Memes, Shibarium, El Hippo, Sonik Coin, Shiba Memu, and Pepe Coin

Best Meme Coins to Buy Now | The Ultimate Guide to Top Crypto Presales and New Meme Coins with ApeMax, Wall Street Memes, Shibarium, El Hippo, Sonik Coin, Shiba Memu, and Pepe Coin

September 19, 2023
Canada’s emerging fund managers get a venture lifeline | BetaKit

Canada’s emerging fund managers get a venture lifeline | BetaKit

September 19, 2023
Valkyrie CIO expects US spot Bitcoin ETF approval in Q2 2024

Valkyrie CIO expects US spot Bitcoin ETF approval in Q2 2024

September 19, 2023
Load More

Discussion about this post

LaLiga NFT Fantasy Soccer Games Coming to North America – Decrypt

LaLiga NFT Fantasy Soccer Games Coming to North America – Decrypt

by Coin Gallery
September 21, 2023

Gaming startup GameOn has a new deal with LaLiga North America to develop NFT-based fantasy games for the Spanish soccer...

Christie’s Turns Keith Haring Digital Art Into NFC-Equipped Patch – Decrypt

Christie’s Turns Keith Haring Digital Art Into NFC-Equipped Patch – Decrypt

by Coin Gallery
September 21, 2023

With five digital drawings from legendary pop artist Keith Haring currently up for sale as NFTs, auction house Christie’s has...

Core DAO Integrates Firehose to Boost DeFi Ecosystem with Faster Data Extraction

Core DAO Integrates Firehose to Boost DeFi Ecosystem with Faster Data Extraction

by DeFi Whiz
September 21, 2023

Core DAO’s Firehose integration will enable developers to extract blockchain data quickly, increasing the efficiency of the blockchain applications they...

Shiba Inu Bitcoin Correlation Drops to Lowest in Weeks, What Happened?

Shiba Inu Bitcoin Correlation Drops to Lowest in Weeks, What Happened?

by Satoshi Disciple
September 21, 2023

Shiba Inu-Bitcoin correlation in the last 30 days has fallen to a new low as Shiba Inu charts its course...

One Whale Trades Majority of Ethereum for Bitcoin

One Whale Trades Majority of Ethereum for Bitcoin

by Chain Master
September 20, 2023

In the cypto world, the actions of significant players, often referred to as 'whales', can provide valuable insights into market...

  • Altcoin
  • Bitcoin
  • Blockchain
  • Canada
  • Cryptocurrency
  • DeFi
  • Ethereum
  • Gaming
  • NFT
news cryptos white 500 x 58

Get the lastest cryptocurrency and blockchain news around the world daily. Learn about more Bitcoin, Ethereum, Altcoin, DeFi, Gaming, and NFTs.

Altcoins 

Bitcoin

Blockchain

Cryptocurrency

DeFi

Ethereum

Gaming

NFTs

Twitter Youtube Facebook Instagram Envelope
  • About
  • Privacy
  • Terms
  • Contact
Subscribe to our Newsletter
Loading

© 2023 News Cryptos. All Rights Reserved.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Altcoin
  • DeFi
  • Gaming
  • NFT
  • Blockchain

© 2023 News Cryptos. All Rights Reserved.