Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
This Trojan exploits antivirus software to steal your data
#1
Quote:Astaroth disguises itself as image and GIF files to infect PCs.

A new strain of the Astaroth Trojan has been given the capability to exploit vulnerable processes in antivirus software and services.
Cybereason's Nocturnus Research team said in a blog post published on Wednesday that the variant is able to utilize modules in cybersecurity software in order to steal online credentials and personal data.
In its latest form, Astaroth is being used in spam campaigns across Brazil and Europe, with thousands of infections recorded at the end of 2018. The malware spreads through .7zip file attachments and malicious links.
The cybersecurity researchers said the Trojan masquerades as a JPEG, .GIF, or an extensionless file to avoid detection when executed on a machine.
If a spam email or phishing messages prove successful and the file is downloaded and opened, the legitimate Microsoft Windows BITSAdmin tool is used to download the full payload from a command-and-control (C2) server.



[Image: read-more.jpg]
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Bitdefender Wins Editors’ Choice at PCMag – ‘The Best Antivirus Software for 2023’ mrtrout 0 532 02-08-2023 , 04:27 PM
Last Post: mrtrout
  Hacker group claims to steal 3 million users’ data from Israeli hiking websites mrtrout 0 1,015 01-22-2022 , 11:03 PM
Last Post: mrtrout
  Are You Cool With Your Antivirus Software Bundling A Crypto Miner? mrtrout 0 595 01-18-2022 , 02:45 AM
Last Post: mrtrout
  Customized Trojan Stole Data From 3M Windows PC Users mrtrout 0 700 07-02-2021 , 05:51 AM
Last Post: mrtrout
  Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws Bjyda 0 891 03-28-2021 , 12:06 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)