Ad End 1 February 2024
Ad Ends 13 January 2025
Ad End 26 February 2025
ad End 25 April 2025
Ad Ends 20 January 2025
Ad expire at 5 August 2024
banner Expire 1 Feb 2025
banner Expire 25 April 2025
What's new
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
casino
swipe store
adv exp at 23 August 2024
Carding.pw carding forum
BidenCash Shop
Kfc CLub

Fake Microsoft Teams Updates Lead To Cobalt Strike Installation

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,651
Reaction score
715
Points
212
Awards
2
  • Somebody Likes you
  • First post
As part of attacks, hackers purchase advertising on search engines to distribute malware.

[IMG]


Ransomware operators use malicious ads to distribute fake Microsoft Teams updates, infect systems with backdoors, and then install Cobalt Strike beacons to compromise the network.

Bleeping Computer got a warning from Microsoft, according to which the criminals used signed binaries and exploited the critical ZeroLogon vulnerability (CVE-2020-1472) to gain administrator access to the network using the SocGholish JavaScript framework.

In one attack, hackers acquired ads on a search engine, causing early search results for Microsoft Teams software to point to a domain under the criminals' control. Clicking on the link loaded a payload that ran a PowerShell script to download more malicious content. The malware also installed a legitimate copy of Microsoft Teams on the system so that victims would not suspect anything.

In most cases, the original payload was the Predator the Thief infostiller, which sends sensitive information such as credentials, browser data, and financial information to an attacker, Microsoft said. Other programs distributed in this way include the Bladabindi backdoor (NJRat) and the ZLoader info-stealer.

The malware also downloaded Cobalt Strike beacons, allowing an attacker to roam the network. In some attacks, the final stage was the launch of malware to encrypt files on computers on the network.

As a reminder, attackers have also begun to actively use a critical vulnerability (CVE-2020-14882) in Oracle WebLogic platforms to deploy Cobalt Strike beacons. Thus, hackers provide themselves with constant remote access to compromised devices.
__________________
 
Ad End 1 February 2024
Top