Tag Archive for: strike

Microsoft Teams Hit by ‘FakeUpdates’ Malware Using Cobalt Strike; Here’s How to Prevent It


Microsoft warned its users about recent “FakeUpdates” campaigns targeting  various types of companies, particularly the education sector that uses Teams videoconferencing app. 

According to a Bleeping Computer as shared by Threat Post, the tech giant warned its customers about the security threat using fake Microsoft Teams update ads as backdoors to infect networks with malware. They use Cobalt Strike in this campaign, which targets the K-12 education and other companies, which are currently dependent on videoconferencing apps such as Microsoft Teams amid the coronavirus pandemic.

Microsoft Teams Is Under Attack by ‘FakeUpdates’ Malware Using Cobalt Strike

(Photo : Microsoft)
Microsoft Teams Is Under Attack by ‘FakeUpdates’ Malware Using Cobalt Strike

Microsoft Teams: ‘FakeUpdates’ Malware Uses Cobalt Strike

According to a report, cyber attackers use Cobalt Strike to infect company networks outside the infection point.

Cobalt Strike is being used by threat actors to spread ransomware and other kinds of malware. It is a commodity attack-simulation tool, which was used in exploiting the privilege-elevation flaw Zerologon that allows attackers to gain access to the domain controller and fully compromise Active Directory identity services.

The Microsoft advisory stated that attackers in the recent FakeUpdates campaign used search-engine ads to promote Teams software top results into a domain that they can use and control for infamous activity. Then, if victims would click the link, it would download a payload and execute a PowerShell script that loads malicious content.

Cybercriminals use Cobalt Strike as payload, so threat actors can laterally move across the network beyond the initial infection system. It also installs a valid Microsoft Teams app on the system, so it seems legitimate and prevents victims from noticing the attack.

‘FakeUpdates’ Malware Uses Cobalt Strike

(Photo : Microsoft)
‘FakeUpdates’ Malware Uses Cobalt Strike

The advisory also stated that the campaign dispenses malware, which include the infostealer Predator the Thief, which steals sensitive data including account credentials, payment data, and browsers. The tech giant also noticed the latest campaigns spreading ZLoader and Bladabindi (NJRat) backdoor.

In…

Source…

Pick your poison: The potential Iranian responses to US drone strike

TEHRAN, IRAN - (ARCHIVE): A file photo dated September 18, 2016 shows Iranian Revolutionary Guards' Quds Force commander Qasem Soleimani during Iranian Supreme Leader Ayatollah Ali Khamenei's meeting with Revolutionary Guards, in Tehran, Iran.

Enlarge / TEHRAN, IRAN – (ARCHIVE): A file photo dated September 18, 2016 shows Iranian Revolutionary Guards’ Quds Force commander Qasem Soleimani during Iranian Supreme Leader Ayatollah Ali Khamenei’s meeting with Revolutionary Guards, in Tehran, Iran. (credit: Anadolu Agency / Getty Images)

The assassination by missile last night of Iranian Revolutionary Guard Corps Quds Force commander Major General Qasem Soleimani and four other senior Iranian officers has triggered vows of revenge from Iran’s Supreme Leader and other members of Iran’s leadership. Those vows have raised concerns about both physical and electronic attacks by Iran against the US and other targets—including an expansion of the already noted broadening attempts at cyber attacks by Iranian state-sponsored hackers.

A Department of Defense spokesperson said in a statement on the attack, “At the direction of the President, the US military has taken decisive defensive action to protect US personnel abroad by killing Qasem Soleimani… General Soleimani was actively developing plans to attack American diplomats and service members in Iraq and throughout the region.”

The attack, apparently launched from a drone against Soleimani’s motorcade as it left Baghdad International Airport, also is reported to have killed Abu Mahdi al-Muhandis, the leader of Iraq’s Kata’ib Hezbollah militia—the force the US blamed for a December 27, 2019 rocket attack on a Peshmerga-operated base that killed a US contractor and wounded several US soldiers there as part of a training operation. Soleimani was alleged by the Defense Department’s spokesperson to have orchestrated that attack, as well as the protest and assault on the US Embassy in Baghdad this week.

Read 7 remaining paragraphs | Comments

Biz & IT – Ars Technica

Good Morning, News: Election Meddling Counter Strike, Christians vs. Trump, and What Is Boxing Day Exactly? – The Portland Mercury

Good Morning, News: Election Meddling Counter Strike, Christians vs. Trump, and What Is Boxing Day Exactly?  The Portland Mercury
“cyber warfare news” – read more