New Toolkit Pushes Malware via Fake Program Update Alerts in 30 Languages
#1
Bug 
Quote:A new social engineering toolkit called Domen has been discovered that uses fake browser and program update alerts on compromised sites to infect users with malware and remote access software.
 
Attackers using fake browser and flash player update alerts to spread malware is nothing new [123], but this new toolkit discovered by Malwarebytes researcher Jérôme Segura has a high level of sophistication and customization that allows it to adapt to different clients, browsers, and visitors.
 
When loaded on a compromised site, the Domen toolkit will display a variety of alerts that overlay the site's legitimate content. These fake alerts are designed to trick users into downloading the "update", executing it, and infecting themselves with a payload of the attacker's choice.
 
"Loaded as an iframe from compromised websites (most of them running WordPress) and displayed over top as an additional layer, it entices victims to install so-called updates that instead download the NetSupport remote administration tool," Segura stated in his report. "In this blog we describe its tactics, techniques and procedures (TTPs) that remind us of some past and current social engineering campaigns."

Read more here: https://www.bleepingcomputer.com/news/se...languages/
[-] The following 3 users say Thank You to silversurfer for this post:
  • dhruv2193, harlan4096, ismail
Reply


Messages In This Thread
New Toolkit Pushes Malware via Fake Program Update Alerts in 30 Languages - by silversurfer - 03 September 19, 17:35

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD suggests it may open-source FSR 4 a...
AMD still has nothin...harlan4096 — 17:21
Intel Arc G3 Panther Lake series for han...
Intel G3 with LPDD...harlan4096 — 07:32
Core Ultra 7 270K Plus and Ultra 5 250K...
Intel reportedly ‘ca...harlan4096 — 11:27
Core Ultra 7 270K Plus and Ultra 5 250K ...
Intel’s Core Ultra...harlan4096 — 11:09
Adobe Acrobat Reader DC 2025.001.21184
Adobe Acrobat Read...harlan4096 — 10:45

[-]
Birthdays
Today's Birthdays
avatar (49)tsorenHievy
Upcoming Birthdays
avatar (47)hapedDow
avatar (46)komriwat
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (41)svoyaEnuct
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>