Geeks for your information
Microsoft Spots Nodersok Malware Campaign That Zombifies PCs - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Microsoft Spots Nodersok Malware Campaign That Zombifies PCs (/showthread.php?tid=8537)



Microsoft Spots Nodersok Malware Campaign That Zombifies PCs - silversurfer - 26 September 19

Quote:A new fileless malicious campaign, dubbed Nodersok by Microsoft Defender ATP Research Team researchers who discovered it, drops its own LOLBins to infect Windows computers with a Node.js-based malware that will turn the devices into proxies.
 
Unlike other fileless malware attacks that only use living-off-the-land binaries (LOLBins) present on the devices they compromise, the attackers behind Nodersok have been observed while also delivering the legitimate Node.exe Node.js framework and the Windows Packet Divert (WinDivert) network packet capture tool to devices they target.
 
The campaign attacked thousands of machines within several weeks, with a focus on home users from U.S. and Europe, with roughly 3% of all attacks also targeting organization from industry sectors such as education, business and professional services, healthcare, finance, and retail.

Read more here: https://www.bleepingcomputer.com/news/security/microsoft-spots-nodersok-malware-campaign-that-zombifies-pcs/


Malware campaign turns PC's into "Zombie Proxies" - dhruv2193 - 30 September 19

Quote:A newly discovered strain of malware transforms PCs into what Microsoft ominously calls “zombie proxies” using otherwise legitimate programs, and the company claims it’s infected thousands of computers across the U.S. and Europe.

Microsoft and Cisco’s Talos researchers both released reports this week that outlined this cyber threat, which the companies call Nodersok and “Divergent” respectively.

Source(full read) https://gizmodo.com/microsoft-cisco-talos-discover-malware-campaign-that-t-1838602134