Technology Today

The cybercriminals behind a recent phishing campaign used a fake Norton LifeLock document in order to trick victims into installing a remote access trojan (RAT) on their systems.The infection begins with a Microsoft Word document that contains malicious macros.

However, to get users to enable macros, which are disabled by default, the threat actor behind the campaign used a fake password-protected Norton LifeLock document.Victims are asked to enable macros and type in a password, provided in the phishing email containing the document, to gain access to it.

Palo Alto Networks' Unit 42, which discovered the campaign, also found that the password dialog box accepts only a upper or lowercase letter 'C'.

If the password is incorrect, the malicious action does not continue.If the user does input the correct password, the macro continues executing and builds a command string that installs the legitimate remote control software, NetSupport Manager.The RAT binary is downloaded and installed onto a user's machine with help from the 'msiexec' command in the Windows Installer service.In a new report, the researchers at  Palo Alto Networks' Unit 42 explained that the MSI payload installs without any warnings and adds a PowerShell script in the Windows temp folder.

This is used for persistence and the script plays the role of a backup solution for installing NetSupport Manager.Before the script continues its operations, it checks to see if an antivirus from either Avast or AVG is installed on the system.

If this is the case, it stops running on the victim's computer.

If the script finds that these programs aren't present on the machine, it adds the files needed b NetSupport Manager to a folder with a random name and also creates a registry key for the main executable named 'presentationhost.exe' for persistence.Unit 42 first discovered the campaign at the beginning of January and the researchers tracked related activity back to November 2019 which shows that the campaign is part of a larger operation.Via BleepingComputer





Unlimited Portal Access + Monthly Magazine - 12 issues-Publication from Jan 2021


Buy Our Merchandise (Peace Series)

 


Contribute US to Start Broadcasting



It's Voluntary! Take care of your Family, Friends and People around You First and later think about us. Its Fine if you dont wish to contribute and if you wish to contribute then think about the Homeless first and Feed them. We can survive with your wishes too :-). You can Buy our Merchandise too which are of the finest quality.

Debit/Credit/UPI

UPI/Debit/Credit

Paytm


STRIPE


Brits spot 'Black Mirror' creature crossing city street as they brand it 'drone on legs'


Millions of UK Netflix users face brand-new material block - check if you are impacted


Fortnite, WhatsApp, imessage and Facetime down: Livid users fume as apps and servers crash


EE includes Google's most recent Pixel 8a phone to its stock, here's why its cost is one to opt for


Let Dyson have your old vacuum and you'll get money off something way better


Apple verifies essential upgrades are coming to the iPhone and iPads this year


Three Mobile will give you free unlimited 5G data but there's a deal that's even better


Argos buyers are getting Samsung TVs at 'most affordable ever' rate which's not all


Your Android phone is getting among the most important complimentary upgrades in years


Popular Android apps are harming your phone - 5 things you must delete immediately


What jobs will AI replace Share your views on the advanced tech


Virgin Media sends out essential text alert to all UK users - check your phone now


Sky dishes out all-new Apple iPads at prices that feel far more affordable


Samsung TV fans get 48-hour countdown to claim free Galaxy S24 - don't miss out


Google issues urgent Chrome update to all UK users - relaunch your browser today


Surprise Samsung Galaxy S24 deal lets you own this phone for less than half-price


Apple simply eliminated one of its most popular products however there's still time to purchase it


Apple launches stellar refurbished iPad deal after price cut


Windows 10 beats Windows 11 again but worrying deadline still looms for millions


Google does record your voice but there's a very simple way to stop it


WhatsApp confirms biggest change to chat app in years and it's coming to your phone soon


Netflix viewers furious following controversial subscription change


Argos and Amazon buyers hurry to get inexpensive AirPods at costs Apple won't match


Urgent WhatsApp chat cautioning issued to all UK users - ignoring it will be pricey





54