News from our Cybersecurity Expert Center
We bring you the latest news and alerts detected from Cybersecurity.
Connect with us by info@netstudio.it
Outstanding cybersecurity news
Vulnerabilities
Severe vulnerability detected in Measuresoft ScadaPro Server (CVE-2022-3263) that would allow execution of malicious commands
cisa.gov
Memory corruption vulnerability in the uClibC library (CVE-2022-29503) affects Unix-based devices
Malware
Malicious OAuth applications used to compromise email servers and spread spam
Malicious NPM discovered masquerading as legitimate software library for Material Tailwind
Cybersecurity
Australian security company Optus claims to have suffered a breach affecting customer data
DESORDEN group leaks more Indonesian company data
Latest threats detected
New widespread campaign of Chromeloader malware
20/9/2022
Executive summary
VMware and Microsoft have issued security advisories due to a new wave of attacks by the Chromeloader malware.
Data
Type:
TLP:
Targets:
Affected assets:
Attack vector:
Tags:
Malware
White
Chrome Browsers
Multiple
Malware
ChromeLoader, Malware
Description
A new widespread campaign of the Chromeloader malware has been detected. During the first quarter of the year, attacks related to this malware increased significantly.
In these campaigns the malware infects Chrome with a malicious extension that redirects user traffic to scam/advertising sites for monetisation per click. After this period the malware evolved into InfoStealer, stealing data stored in browsers and retaining adware functions.
Technical details
During the last week a new large-scale click fraud campaign has been identified and attributed to a threat actor named DEV-0796 that makes use of Chromeloader among its artefacts.
This campaign starts with ISO files that are delivered via malicious advertisements, browser redirects and YouTube video comments. Once the ISO file is mounted on the system, 4 files are visible.
A compressed ZIP file containing the malware in question, an ICON file, a .bat file (in most campaigns it is named resources.bat) that is responsible for installing the malware and a Windows shortcut that starts the .bat file.
Some of the campaigns mimic popular applications such as music players like FLB, OpenSubtitle for movie subtitles and TV shows.
Chromeloader has also implemented "ZipBombs" files that once executed destroy the user's system by overloading it with data as well as distributing Enigma ransomware in HTML files.
Recommendations
Protection
Detection
Mitigation
Telefono: +39 0574.514180
SIA, an Indra Group company, is the Indra Group's specialized cybersecurity company. It offers technologically advanced solutions and innovative services, taking the concept of cybersecurity one step further.
Indra is one of the leading global technology and consulting companies: the technology partner for key operations of client businesses worldwide.
Telefono: +39 0574.514180
SIA, an Indra Group company, is the Indra Group's specialized cybersecurity company. It offers technologically advanced solutions and innovative services, taking the concept of cybersecurity one step further.
Indra is one of the leading global technology and consulting companies: the technology partner for key operations of client businesses worldwide.