Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • We Have Hundreds of Blockchain Patents — But Regulation Won’t Allow Us to Engage in Crypto – Regulation Bitcoin News bitcoin news
  • Cryptocurrency Can Potentially Complement Mobile Money Argues Kenyan Banker – Emerging Markets Bitcoin News bitcoin news
  • Bitcoin Tumbles Below $36K, Altcoins In Red Too bitcoin news
  • Is It Time To Buy Bitcoin? bitcoin news
  • ‘Mathematics Don’t Account for Human Emotions’ – News Bitcoin News bitcoin news
  • AVAX, ALGO Among Crypto Losers as U.S. Inflation Hits 40-Year High – Market Updates Bitcoin News bitcoin news
  • Bitcoin Regains Some Luster With 15% Rally To $21,700 bitcoin news
  • Why Bitcoin And Stablecoin Dominance Is On The Rise bitcoin news

Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware

Posted on May 20, 2022 By root


Adobe Photoshop

Fraudulent domains masquerading as Microsoft’s Windows 11 download portal are attempting to trick users into deploying trojanized installation files to infect systems with the Vidar information stealer malware.

“The spoofed sites were created to distribute malicious ISO files which lead to a Vidar info-stealer infection on the endpoint,” Zscaler said in a report. “These variants of Vidar malware fetch the C2 configuration from attacker-controlled social media channels hosted on Telegram and Mastodon network.”

Some of the rogue distribution vector domains, which were registered last month on April 20, consist of ms-win11[.]com, win11-serv[.]com, and win11install[.]com, and ms-teams-app[.]net.

In addition, the cybersecurity firm cautioned that the threat actor behind the impersonation campaign is also leveraging backdoored versions of Adobe Photoshop and other legitimate software such as Microsoft Teams to deliver Vidar malware.

The ISO file, for its part, contains an executable that’s unusually large in size (over 300MB) in an attempt to evade detection by security solutions and is signed with an expired certificate from Avast that was likely stolen following the latter’s breach in October 2019.

But embedded within the 330MB binary is a 3.3MB-sized executable that’s the Vidar malware, with the rest of the file content padded with 0x10 bytes to artificially inflate the size.

In the next phase of the attack chain, Vidar establishes connections to a remote command-and-control (C2) server to retrieve legitimate DLL files such as sqlite3.dll and vcruntime140.dll to siphon valuable data from compromised systems.

CyberSecurity

Also notable is the abuse of Mastodon and Telegram by the threat actor to store the C2 IP address in the description field of the attacker-controlled accounts and communities.

The findings add to a list of different methods that have been uncovered in the past month to distribute the Vidar malware, including Microsoft Compiled HTML Help (CHM) files and a loader called Colibri.

“The threat actors distributing Vidar malware have demonstrated their ability to social engineer victims into installing Vidar stealer using themes related to the latest popular software applications,” the researchers said.

“As always, users should be cautious when downloading software applications from the Internet and download software only from the official vendor websites.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
Next Post: Dubai Couple Ties the Knot in the Metaverse – Metaverse Bitcoin News

Related Posts

  • New ‘FabricScape’ Bug in Microsoft Azure Service Fabric Impacts Linux Workloads cyber security news
  • 7 Key Findings from the 2022 SaaS Security Survey Report cyber security news
  • BlackCat Ransomware Gang Targeting Unpatched Microsoft Exchange Servers cyber security news
  • U.S. FCC Commissioner Asks Apple and Google to Remove TikTok from App Stores cyber security news
  • Chinese “Override Panda” Hackers Resurface With New Espionage Attacks cyber security news
  • High-Severity RCE Vulnerability Reported in Popular Fastjson Library cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Storj (STORJ) – A Relatively Unheard Crypto bitcoin news
  • Cardano Vasil Hard Fork Launch Date Set, Time To Buy The News? bitcoin news
  • Microsoft Finds Critical Bugs in Pre-Installed Apps on Millions of Android Devices cyber security news
  • Crypto Hedge Fund 3 Arrows Capital (3AC) Files For Bankruptcy bitcoin news
  • Ripple Price Falls Below $0.43 As Bears Take Control Of The Market bitcoin news
  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News bitcoin news
  • EU Makes Deal on MiCA Legislation to Regulate Crypto Markets – Regulation Bitcoin News bitcoin news
  • WAVES Nearly 60% Higher, as AXS Surges Close to 25% in Today’s Session – Market Updates Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme