Dismiss this notice
WinRAR forever! Father's Day 2019 Giveaway - [Only registered and activated users can see links Click here to register]

Dismiss this notice
Avast Premier Photo Caption - [Only registered and activated users can see links Click here to register]

Dismiss this notice
FastestVPN Accounts Giveaway - [Only registered and activated users can see links Click here to register]


Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
This Trojan exploits antivirus software to steal your data
#1
Quote:New banking trojan malware getting ready for a global campaign, experts warn
A new strain of the Astaroth Trojan has been given the capability to exploit vulnerable processes in antivirus software and services.

Cybereason's Nocturnus Research team said in a blog post published on Wednesday that the variant is able to utilize modules in cybersecurity software in order to steal online credentials and personal data.  

 
In its latest form, Astaroth is being used in spam campaigns across Brazil and Europe, with thousands of infections recorded at the end of 2018. The malware spreads through .7zip file attachments and malicious links.

The cybersecurity researchers said the Trojan masquerades as a JPEG, .GIF, or an extensionless file to avoid detection when executed on a machine.

If a spam email or phishing messages prove successful and the file is downloaded and opened, the legitimate Microsoft Windows BITSAdmin tool is used to download the full payload from a command-and-control (C2) server.

After initializing, the malware launches an XSL script which establishes a channel with the C2 server. The script, which is obfuscated, contains functions to hide itself from antivirus software and is responsible for the process which leverages BITSAdmin to download payloads, including Astaroth, from a separate C2 server.

[Only registered and activated users can see links Click here to register]
[-] The following 2 users Like Toligo's post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Recent Posts
GIMP 2.10.12
GIMP 2.10.12 GIMP...damien76 — 19:00
[Giveaway] WinX HD Video Converter Delu...
WinX HD Video Conver...ismail — 18:57
AnyMP4 Screen Recorder Professional 1.2....
The best tool for...ismail — 18:53
Shotcut 19.06.15
Shotcut 19.07.15 (15...damien76 — 18:51
InPixio Photo Editor 9 [for PC]
Easily transform ...ismail — 18:47

[-]
Birthdays
Today's Birthdays
avatar (34)papedDow
avatar (43)ArnoldFum
avatar (31)yfaza
Upcoming Birthdays
avatar (36)lapedDow
avatar (42)rituabew
avatar (30)omyjul
avatar (32)boineDon
avatar (34)vkseogaF
avatar (30)usogy
avatar (33)ywixazok

[-]
Online Staff
There are no staff members currently online.

>