Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • The Nightly Mint: Daily NFT Recap bitcoin news
  • Cleveland Fed President Loretta Mester Is ‘Not Predicting a Recession,’ Says Inflation Will Move Down – Economics Bitcoin News bitcoin news
  • Credibility Concerns — Gallop Poll Shows Fed Chair’s Confidence Ratings Slid by Double Digits – News Bitcoin News bitcoin news
  • How The Crypto Winter Has Impacted The DeFi Sector bitcoin news
  • Nearly 100,000 NPM Users’ Credentials Stolen in GitHub OAuth Breach cyber security news
  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • Internet Service Company Cloudflare to Run Ethereum Validator Nodes as Part of Its Web3 Focus – Bitcoin News bitcoin news
  • A Dot Com Magnitude Crash To Rock The Crypto Market? bitcoin news

Russian Hackers Exploiting Microsoft Follina Vulnerability Against Ukraine

Posted on June 22, 2022 By root


Microsoft Follina Vulnerability

The Computer Emergency Response Team of Ukraine (CERT-UA) has cautioned of a new set of spear-phishing attacks exploiting the “Follina” flaw in the Windows operating system to deploy password-stealing malware.

Attributing the intrusions to a Russian nation-state group tracked as APT28 (aka Fancy Bear or Sofacy), the agency said the attacks commence with a lure document titled “Nuclear Terrorism A Very Real Threat.rtf” that, when opened, exploits the recently disclosed vulnerability to download and execute a malware called CredoMap.

Follina (CVE-2022-30190, CVSS score: 7.8), which concerns a case of remote code execution affecting the Windows Support Diagnostic Tool (MSDT), was addressed by Microsoft on June 14, 2022, as part of its Patch Tuesday updates.

CyberSecurity

According to an independent report published by Malwarebytes, CredoMap is a variant of the .NET-based credential stealer that Google Threat Analysis Group divulged last month as having been deployed against users in Ukraine.

The malware’s main purpose is to siphon data, including passwords and saved cookies, from several popular browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox.

Russian Hackers Targeting Ukraine
Russian Hackers Targeting Ukraine

“Although ransacking browsers might look like petty theft, passwords are the key to accessing sensitive information and intelligence,” Malwarebytes said. “The target, and the involvement of APT28, a division of Russian military intelligence), suggests that campaign is a part of the conflict in Ukraine, or at the very least linked to the foreign policy and military objectives of the Russian state.”

CyberSecurity

It’s not just APT28. CERT-UA has further warned of similar attacks mounted by Sandworm and an actor dubbed UAC-0098 that leverage a Follina-based infection chain to deploy CrescentImp and Cobalt Strike Beacons on to targeted hosts.

The development comes as Ukraine continues to be a target for cyberattacks amidst the country’s ongoing war with Russia, with Armageddon hackers also spotted distributing the GammaLoad.PS1_v2 malware in May 2022.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Bitcoin Steady Above $20K After Drop To $17K
Next Post: ETH Down, as Two-Day Winning Streak Ends on Hump Day – Market Updates Bitcoin News

Related Posts

  • Experts Detail Saintstealer and Prynt Stealer Info-Stealing Malware Families cyber security news
  • SideWinder Hackers Launched Over a 1,000 Cyber Attacks Over the Past 2 Years cyber security news
  • Android and Chrome Users Can Soon Generate Virtual Credit Cards to Protect Real Ones cyber security news
  • Chinese Hackers Distribute Backdoored Web3 Wallets for iOS and Android Users cyber security news
  • Google Blocks Dozens of Malicious Domains Operated by Hack-for-Hire Groups cyber security news
  • Russian Hackers Targeting Diplomatic Entities in Europe, Americas, and Asia cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Critical Gems Takeover Bug Reported in RubyGems Package Manager cyber security news
  • The Nightly Mint: Daily NFT Recap bitcoin news
  • ZuoRAT Malware Hijacking Home-Office Routers to Spy on Targeted Networks cyber security news
  • Bitcoin Dips Further, Why BTC Could Revisit $20K bitcoin news
  • LUNA 2.0 Suffers Significant Price Correction Hours After Launch bitcoin news
  • Ethereum Transfer Costs Continue to Slide — Network Fees Tap a 19-Month Low – Altcoins Bitcoin News bitcoin news
  • Terra Community Plans to Vote on Forking the Chain — Launch May Airdrop a Billion New Tokens to Network Participants – Bitcoin News bitcoin news
  • Warner Bros. and Nifty’s to Launch Looney Tunes Story Bolstered by NFTs – Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme