Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Sodinokibi Ransomware Spreads via Fake Forums on Hacked Sites
#1
Quote:A distributor for the Sodinokibi Ransomware is hacking into WordPress sites and injecting JavaScript that displays a fake Q & A forum post over the content of the original site. This fake post contains an "answer" from the site's "admin" that contains a link to the ransomware installer.

As security software and people become more aware of the methods that are used to distribute ransomware and malware, affiliates need to come up with craftier methods to infect their victims.

Such is the case with a new distribution method that overlays a fake Questions and Answers forum on top of the content of a hacked site. This fake forum post will contain information related to the content of the page that the user is visiting, so it appears that the answer and link offered by the admin is legitimate.

In reality, though, the downloaded file will infect the user with the Sodinokibi, or REvil, Ransomware.


[Image: UwmqttI.png]
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Fake TSA PreCheck sites scam US travelers with fake renewals mrtrout 0 505 11-20-2021 , 11:55 PM
Last Post: mrtrout
  FBI's Email System Hacked to Send Out Fake Cyber Security Alert to Thousands mrtrout 0 552 11-16-2021 , 05:20 AM
Last Post: mrtrout
  Ryuk ransomware now self-spreads to other Windows LAN devices mrtrout 0 847 02-26-2021 , 09:40 PM
Last Post: mrtrout
  Wroba Mobile Banking Trojan Spreads to the U.S. via Texts mrtrout 0 903 10-31-2020 , 09:51 AM
Last Post: mrtrout
  Mac malware spreads through Xcode projects mrtrout 0 782 08-15-2020 , 10:54 PM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)