banner Expire 25 October 2025
adv exp at 30 July 2025
banner Expire 10 February 2026
Ad End 1 November 2025
ad End 5 May 2025
ad End 25 October 2025
Ad End 4 April 2026
What's new
UniCvv
banner Expire 20 October 2024
banner Expire 15 January 2025
Money Club cc shop
Wizard's shop 2.0
Ad Ends 13 July 2025
Carding Game
BidenCash Shop
Carding.pw carding forum
Kfc CLub
Yale Lodge
best shop

Fake Microsoft Teams Updates Lead To Cobalt Strike Installation

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,852
Reaction score
739
Points
212
Awards
2
  • Somebody Likes you
  • First post
As part of attacks, hackers purchase advertising on search engines to distribute malware.

[IMG]


Ransomware operators use malicious ads to distribute fake Microsoft Teams updates, infect systems with backdoors, and then install Cobalt Strike beacons to compromise the network.

Bleeping Computer got a warning from Microsoft, according to which the criminals used signed binaries and exploited the critical ZeroLogon vulnerability (CVE-2020-1472) to gain administrator access to the network using the SocGholish JavaScript framework.

In one attack, hackers acquired ads on a search engine, causing early search results for Microsoft Teams software to point to a domain under the criminals' control. Clicking on the link loaded a payload that ran a PowerShell script to download more malicious content. The malware also installed a legitimate copy of Microsoft Teams on the system so that victims would not suspect anything.

In most cases, the original payload was the Predator the Thief infostiller, which sends sensitive information such as credentials, browser data, and financial information to an attacker, Microsoft said. Other programs distributed in this way include the Bladabindi backdoor (NJRat) and the ZLoader info-stealer.

The malware also downloaded Cobalt Strike beacons, allowing an attacker to roam the network. In some attacks, the final stage was the launch of malware to encrypt files on computers on the network.

As a reminder, attackers have also begun to actively use a critical vulnerability (CVE-2020-14882) in Oracle WebLogic platforms to deploy Cobalt Strike beacons. Thus, hackers provide themselves with constant remote access to compromised devices.
__________________
 
Ad End 1 November 2024
Top